ConnectWise issues temporary workaround for unpatched ScreenConnect vulnerability

ConnectWise has disclosed a new vulnerability in ScreenConnect that affects file transfer behavior in remote access sessions, with no permanent fix yet available. The company provides temporary mitigation steps, including disabling the TransferFiles permission for user roles. The flaw impacts both cloud and on-premises deployments, and ConnectWise plans to release a patch later this week.
The vendor advises administrators to navigate to the Administration page, select Security, then Roles, and uncheck the TransferFiles permission within Scoped Permissions for each session group. This interim measure applies to both hosted and self-managed environments, with a permanent software update expected shortly.
The platform is a frequent target for cybercriminals, with roughly 6,000 internet-facing instances currently tracked. Past exploits have involved ransomware operations and state-sponsored actors, leading to CISA's inclusion of three ScreenConnect flaws in its known exploited vulnerabilities catalog since 2024.
Managed service providers and IT departments relying on ScreenConnect could face operational disruption if they apply the temporary fix, as disabling file transfer may hinder routine maintenance tasks. Meanwhile, unpatched instances may remain exposed to malicious actors seeking to exfiltrate sensitive data or deploy ransomware. The absence of a permanent patch creates a critical window where organizations must balance security against workflow continuity, potentially affecting thousands of businesses that depend on remote support tools.