ConnectWise has disclosed a new vulnerability in ScreenConnect Remote Access and shared temporary mitigation measures while it prepares a permanent fix later this week.
The flaw affects both cloud-hosted and on-premises deployments. ConnectWise said the issue affects file-transfer behavior in ScreenConnect Remote Access Support and Access sessions. The vulnerability does not yet have a CVE ID.
Shadowserver is tracking nearly 6,000 ScreenConnect instances exposed online, although it has not reported how many are honeypots or have already been secured. ConnectWise said ScreenConnect vulnerabilities are frequently targeted by financially motivated and state-backed hacking groups.
In 2024, ransomware groups and the Kimsuky North Korean APT exploited another ScreenConnect flaw, CVE-2024-1709, to deliver malware. In the previous year, ConnectWise said suspected state-sponsored hackers used the high-severity ViewState code-injection vulnerability CVE-2025-3935 to access cloud-based instances belonging to a limited number of customers.
In March, ConnectWise also addressed a ScreenConnect cryptographic signature-verification vulnerability, CVE-2026-3564, which could allow attackers to hijack unpatched instances. Since February 2024, CISA has added three ScreenConnect vulnerabilities to its catalog of actively exploited flaws; two were also used in ransomware attacks.
Comments
0No comments yet. Be the first to comment.