ConnectWise Warns of New ScreenConnect Remote Access Flaw – Released Mitigation Steps

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

ConnectWise has warned customers about a newly identified security issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions.

The issue impacts both cloud-hosted and on-premises ScreenConnect deployments, and the company has released interim mitigation guidance while it develops a permanent fix.

The advisory, published on September 3, 2026, does not yet include a CVE identifier. ConnectWise said a CVE and an official patched release are expected within the week after cloud environment updates are rolled out.

The issue affects CW Remote Access, formerly associated with ScreenConnect, specifically within Support and Access sessions. ConnectWise has not disclosed technical details about how the file transfer behavior could be abused, the attack scenarios involved, or whether exploitation has been observed in the wild.

However, the company urged partners and administrators to act immediately by restricting technician file-transfer privileges. Remote access platforms are high-value targets because they can provide attackers with direct access to managed endpoints, internal systems, and sensitive customer environments.

ConnectWise Released Mitigation Steps

The advisory applies to ScreenConnect Remote Access instances deployed via the ConnectWise cloud infrastructure, as well as to self-hosted installations.

Organizations using ScreenConnect for remote support should review user roles, session groups, and file-transfer permissions across their environment.

Until the official update is released, ConnectWise recommends restricting file-transfer access for technicians. Administrators can apply the change without upgrading ScreenConnect or installing a new version.

To reduce exposure, administrators should log in to the ScreenConnect Administration page and open the Security and Roles section. They should then edit every role assigned to users and inspect the session groups configured with permissions.

Within the Scoped Permissions window, administrators need to check whether the TransferFiles permission is enabled. Older ScreenConnect versions may instead use the TransferFilesInSession permission. If either permission is selected, it should be removed.

The updated role configuration must be saved, and the same review should be repeated for every role defined in the cloud tenant or on-premises installation. Turning off these permissions prevents technicians from transferring files through affected remote-access sessions.

While this may temporarily disrupt support workflows that depend on file exchange, it reduces the potential attack surface until ConnectWise releases its final remediation.

ConnectWise said it is developing a fix for the underlying file-transfer behavior and plans to publish additional guidance once the update becomes available. The company will also assign a CVE identifier after its cloud rollout is completed.

Organizations should monitor the ConnectWise advisory page for the patched release, CVE details, affected-version information, and any new detection or response guidance.

  1. Log in to the ScreenConnect Administration page.
  2. Go to Administration > Security > Roles.
  3. Edit each role assigned to ScreenConnect users or technicians.
  4. Review all applicable session groups and open Scoped Permissions.
  5. Disable TransferFiles or, for legacy versions, TransferFilesInSession.
  6. Save the changes.
  7. Repeat the process for all configured roles.

Security teams should also review ScreenConnect administrative accounts, confirm that only authorized users have privileged roles, and monitor remote-support activity for unusual file-transfer attempts or unexpected changes to role permissions.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post ConnectWise Warns of New ScreenConnect Remote Access Flaw – Released Mitigation Steps appeared first on Cyber Security News.