bleeping-computer · Crawled Sep 8, 2026
ConnectWise warns of new ScreenConnect flaw without patch
1 Actors
Read original article ↗
AI Summary
ConnectWise has identified a vulnerability in its ScreenConnect remote access platform that affects both cloud and on-premises deployments, specifically related to insecure file transfer behavior. A CVE ID has not yet been assigned, and no patch is currently available, though temporary mitigations are recommended. The vulnerability could allow attackers to abuse file transfer permissions during sessions, posing a risk to managed service providers and IT support teams. Given the history of exploitation of ScreenConnect flaws by ransomware groups and state-backed actors, this issue is considered high risk.
AI-extracted · verify before operational use
Extracted Entities 1 found
MITRE ATT&CK TTPs 8 techniques
T1027 Obfuscated Files or Information · Defense Evasion T1053.005 Scheduled Task · Execution T1059.001 PowerShell · Execution T1069.001 Local Groups · Discovery T1071.003 Mail Protocols · Command And Control T1082 System Information Discovery · Discovery T1204.002 Malicious File · Execution T1566 Phishing · Initial Access