MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-07 · via BleepingComputer

ConnectWise issues temporary workaround for unpatched ScreenConnect vulnerability

Image via BleepingComputer
Image via BleepingComputer

ConnectWise has disclosed a new vulnerability in ScreenConnect that affects file transfer behavior in remote access sessions, with no permanent fix yet available. The company provides temporary mitigation steps, including disabling the TransferFiles permission for user roles. The flaw impacts both cloud and on-premises deployments, and ConnectWise plans to release a patch later this week.

Expanded Detail

The vendor advises administrators to navigate to the Administration page, select Security, then Roles, and uncheck the TransferFiles permission within Scoped Permissions for each session group. This interim measure applies to both hosted and self-managed environments, with a permanent software update expected shortly.

The platform is a frequent target for cybercriminals, with roughly 6,000 internet-facing instances currently tracked. Past exploits have involved ransomware operations and state-sponsored actors, leading to CISA's inclusion of three ScreenConnect flaws in its known exploited vulnerabilities catalog since 2024.

Context

Managed service providers and IT departments relying on ScreenConnect could face operational disruption if they apply the temporary fix, as disabling file transfer may hinder routine maintenance tasks. Meanwhile, unpatched instances may remain exposed to malicious actors seeking to exfiltrate sensitive data or deploy ransomware. The absence of a permanent patch creates a critical window where organizations must balance security against workflow continuity, potentially affecting thousands of businesses that depend on remote support tools.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “ConnectWise warns of new ScreenConnect flaw without patch.” Browse more stories.