ConnectWise confirmed a file transfer flaw in ScreenConnect Remote Access Support and Access sessions affecting both Cloud and On-Premise deployments, with a CVE and official fix expected within the week. Huntress found rogue ScreenConnect clients used in social-engineering attacks to spread VBScript payloads, persist on systems, and enable worm-like propagation across newly connected machines. #ScreenConnect #ConnectWise #Huntress #WindowsScriptHost
Keypoints
- ScreenConnect has a file transfer flaw affecting Cloud and On-Premise deployments.
- ConnectWise said a CVE and official fix will be issued within the week.
- Huntress linked rogue ScreenConnect instances to social-engineering-based compromise.
- The attack used VBScript files and Windows registry persistence to spread malware-like activity.
- ConnectWise recommends disabling file transfers, and Huntress advises checking audit logs and reimaging impacted machines.
Read More: https://www.helpnetsecurity.com/2026/09/07/connectwise-screenconnect-file-transfer-flaw/