ConnectWise Warns of Unpatched ScreenConnect Vulnerability in Remote Access Tool
AI-generated from multiple sources. Verify before acting on this reporting.
CONNECTWISE, a leading provider of IT management software, issued an urgent security advisory on Monday warning administrators of a critical vulnerability in its ScreenConnect remote access solution. The flaw, identified on September 7, 2026, affects file transfer operations within both Support and Access sessions, potentially allowing unauthorized actors to manipulate data flows or execute malicious code if exploited.
The company stated that the security defect has not yet been assigned a Common Vulnerabilities and Exposures (CVE) identifier. ConnectWise described the issue as a newly identified flaw in the software's handling of file transfers during active remote sessions. While a permanent patch is under development, the vendor immediately released temporary mitigation measures designed to help IT administrators secure their environments until a full fix is deployed.
ScreenConnect, now rebranded as ScreenConnect by ConnectWise, is widely used by IT professionals and managed service providers to provide remote support and access to client systems. The vulnerability specifically targets the mechanism used to move files between the host machine and the remote user's device during a session. Security experts note that flaws in this area can lead to unauthorized file uploads or downloads, potentially compromising sensitive data or introducing malware into corporate networks.
ConnectWise advised all users of the software to implement the recommended temporary workarounds immediately. The advisory outlines specific configuration changes and operational restrictions intended to neutralize the risk associated with the file transfer function. Administrators are urged to review their current deployment settings and apply these mitigations across all instances of the software to prevent potential exploitation.
The company has not disclosed whether any systems have already been compromised by this vulnerability or if active exploitation has been observed in the wild. ConnectWise representatives declined to comment on the timeline for a permanent patch but emphasized that their engineering teams are working to resolve the issue as quickly as possible. The lack of a CVE ID suggests the vulnerability is being handled under an emergency disclosure protocol, often reserved for critical flaws requiring immediate attention before formal cataloging.
As organizations scramble to apply the temporary fixes, questions remain regarding the full scope of the vulnerability and whether it affects older versions of the software still in use by some enterprises. ConnectWise has not yet specified which versions are vulnerable or if the flaw impacts on-premise installations differently than cloud-hosted versions. The situation remains fluid as the vendor continues to assess the threat landscape and finalize a permanent remediation strategy.