ConnectWise flags ScreenConnect file transfer flaw
ConnectWise's 3 September 2026 ScreenConnect advisory covers a file transfer issue on cloud and on-prem, with no CVE yet and a fix promised within the week. Disable TransferFiles or TransferFilesInSession on every technician role. Shadowserver tracks nearly 6,000 internet-exposed instances.

ConnectWise issued a ScreenConnect security advisory on Thursday, 3 September 2026. BleepingComputer quotes the company: it "has identified an issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions." The issue covers both cloud-hosted and on-premises deployments.
This is a vendor security advisory and mitigation notice. It is not a CISA Known Exploited Vulnerabilities listing, and it is not a patched CVE bulletin. ConnectWise said a CVE identifier and an official fix will be issued within the week. That calendar can move.
The temporary mitigation needs no version upgrade. In Administration > Security > Roles, deselect TransferFiles (or TransferFilesInSession on legacy builds) for technician roles, for each session group. Help Net Security reports ConnectWise's wording that the change can be applied immediately, and that administrators must repeat it for every applicable role.
Help Net also carries Huntress guidance: give extra scrutiny to on-premises installs, and check audit logs for RunFiles or RanFiles tied to a guest process. Reimage compromised hosts from known-good media. A 7 September Help Net update says ConnectWise has not confirmed a technical link between this file transfer flaw and the rogue-client worm Huntress described. Treat those as separate tracks until a vendor note ties them.
Shadowserver, via BleepingComputer, tracks nearly 6,000 ScreenConnect instances exposed online. How many of those are honeypots is not broken out. Prior ScreenConnect abuse, including the 2024 CVE-2024-1709 wave, is background on the product, not proof of a nation-state campaign for this advisory.
Internet-facing remote-access tools sit next to SonicWall SMA 1000 zero-days and the JFrog Artifactory auth bypass. Credential-after-access stories this week also include Contagious Interview macOS OtterCookie.
If you run ScreenConnect for MSP or IT support, disable TransferFiles / TransferFilesInSession on every technician role today, then watch ConnectWise for the CVE and patch drop this week before turning file transfer back on.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free