ConnectWise has issued temporary mitigations for a newly discovered ScreenConnect Remote Access vulnerability that affects both cloud and on-premises deployments and will be patched later this week. The flaw comes as ScreenConnect continues to be targeted in the wild, with nearly 6,000 exposed instances tracked online and prior abuse linked to ransomware groups, Kimsuky, and other attackers. #ConnectWise #ScreenConnect #Kimsuky #CVE-2024-1709 #CVE-2025-3935 #CVE-2026-3564
Keypoints
- ConnectWise found a file transfer issue in ScreenConnect Remote Access sessions.
- The flaw affects both cloud-hosted and on-premises deployments.
- A permanent patch is planned for later this week.
- Administrators are told to disable TransferFiles permissions as a temporary mitigation.
- ScreenConnect has been repeatedly abused by ransomware gangs and state-backed threat actors.