Security1 publisher2 min readPublished
ConnectWise says the fix arrives later this week. Until it does, the only step it offers is a hand-edited per-role permission change that turns off file transfer inside support sessions, on cloud and on-premises alike.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
"ConnectWise has identified an issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions" is the entire technical description on offer [2]. As reported by BleepingComputer, the advisory does not state whether the flaw is reachable without authentication, what a successful attacker obtains, or whether anyone has used it [11]. The advisory carries no CVE [3], and it lacks the kind of indicator that would let an administrator go back through last month's session logs and check [11].
So the mitigation is a permissions change made by hand. Administrators open the ScreenConnect Administration page, go to Administration > Security > Roles, and deselect TransferFiles, or TransferFilesInSession on legacy builds, for every session group in the Scoped Permissions window of every role [5]. The work scales with roles multiplied by session groups. Because ConnectWise calls the step temporary and expects to ship a fix in the same week, each of those toggles gets touched twice: cleared now, restored after the patch [13].
Shadowserver's count of nearly 6,000 exposed instances is a ceiling on internet-reachable consoles rather than a count of affected ones, since the split between honeypots and already-secured hosts is not published [6][14]. On-premises operators set their own patch timing, but cloud tenants get the code fix on ConnectWise's schedule, which leaves the role edit as the only control they hold this week [15].
The reason an undescribed file-transfer bug in this product still warrants the role edits is the run of exploitation behind it. ConnectWise's platform is regularly targeted by both financially motivated and state-backed groups [16]. CVE-2024-1709 was used in 2024 by ransomware gangs and by the North Korean group Kimsuky to drop malware [7]. CVE-2025-3935, a ViewState code injection bug, was the route suspected state-sponsored intruders took into ConnectWise itself, reaching the cloud instances of a limited number of customers [8]. March brought CVE-2026-3564, a cryptographic signature verification flaw that allowed hijacking of unpatched instances [9]. Three ScreenConnect bugs have entered CISA's actively exploited catalog since February 2024, two of them also used in ransomware [10], which across the 25 months to that March fix averages one listing every eight months [12].
The patch date is what decides the cost here. If ConnectWise ships when it said it would, stripping TransferFiles from exposed instances buys a few days of technicians moving files some other way. If the date slips, the consoles still offering the feature are offering the one the vendor singled out, and no log will settle afterwards whether it was used [11].
Ranked by verification strength, evidence, and original report placement.
ScreenConnect is an on-premises or cloud-hosted remote access platform typically used by managed service providers, IT departments and support teams for troubleshooting, patching and system maintenance.
In a security advisory issued on Thursday, ConnectWise said: "ConnectWise has identified an issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions," and shared temporary mitigation measures for the vulnerability.
The security flaw affects both cloud and on-premises ScreenConnect deployments and has not yet received a CVE ID for tracking.
ConnectWise plans to patch the flaw later this week and is still working on a permanent fix, having provided temporary mitigation steps designed to block potential attacks in the meantime.
The mitigation requires administrators to log in to the ScreenConnect Administration page, go to Administration > Security > Roles, edit user roles and check session groups with permissions assigned, deselect the TransferFiles permission (or TransferFilesInSession for legacy) for each session group in the Scoped Permissions window, save, and repeat for all roles.
Shadowserver currently tracks nearly 6,000 ScreenConnect instances exposed online, with no information on how many of these are honeypots or have already been secured.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One advisory, one outlet
The technical basis for the whole story is a single quoted sentence about file transfer behavior, relayed by BleepingComputer alone. There is no CVE, no affected build list, no impact statement and no claim of exploitation to check against. What is verifiable is the mitigation click path and the run of earlier ScreenConnect flaws with published identifiers; what nobody outside ConnectWise can yet see is why file transfer needs switching off.
Exposure counted, response unmeasured
Shadowserver's near-6,000 exposed consoles is the only hard number, and it measures reachability rather than impact, since the decoy and already-hardened share is unstated. Nobody has counted how many administrators have cleared the TransferFiles permission, and the reversal after the patch is unmeasured by construction because the patch has not shipped.
Severity borrowed from earlier bugs
ConnectWise says only that file transfer behavior is affected, and BleepingComputer's headline stays close to that. The weight the story carries comes from its surroundings: the 2024 abuse of CVE-2024-1709 by ransomware crews and Kimsuky, the intrusion into ConnectWise's own systems a year later, and three CISA exploited-vulnerability listings since February 2024. That history is accurate, and none of it says whether this issue has been attacked.
Vendor writes the disclosure and owns the clock
ConnectWise controls the single technical sentence, the definition of what counts as affected, and the date the fix lands. A sparse advisory with no identifier attached is also the version that gives attackers and customers the least to work with, and cloud tenants have no independent way to verify their own exposure. On the publishing side, BleepingComputer's page ends with a pitch for a vendor-sponsored defence report, which touches none of the reporting but belongs on the record.
Firm on procedure, thin on substance
The steps an administrator has to take are specific enough to follow and would be trivially falsified if wrong, so that half of the story holds up. The severity question rests on a document no second outlet has read and an identifier that does not exist yet, which keeps this a mitigation notice rather than a risk assessment.
security
CVE-2026-86218 gives unauthenticated attackers code execution on N-able N-central consoles4 publishers
security
Rogue ScreenConnect clients are pushing VBScripts to every endpoint that connects3 publishers
security
One malformed CIP message faults a Logix controller until someone power-cycles it1 publisher
build
A UDP socket carries Frag Gap from inside a container into host kernel memory1 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · September 7, 2026