Security1 publisher2 min readPublished
CISA gives federal agencies three days to fix the ScreenConnect flaw already under attack
ConnectWise's stopgap is to switch off file transfers in ScreenConnect, and with CISA's exploited-flaw listing now carrying a three-day federal deadline, more than 1,000 exposed servers still run the unpatched build.
The Watch · Security desk

What happened
- CISA added a ConnectWise ScreenConnect missing-authorization flaw to its actively exploited catalog on Friday and ordered U.S. federal agencies to secure their systems within three days.
- ConnectWise published temporary mitigation on September 7, telling security teams to disable TransferFiles permissions.
- It is the fourth ScreenConnect issue CISA has flagged as actively exploited since 2024, and two of the earlier ones were abused in ransomware attacks.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure ScreenConnect servers sit above managed customer endpoints, so an attacker who abuses the file transfer path on one MSP console inherits execution on every machine that console maintains.
- constraint The stopgap costs help-desk capability: TransferFiles is how technicians move files during troubleshooting and patching, and switching it off takes that away until the fixed build is deployed.
- decision Federal agencies have a date. Everyone else picks one, and the choice is between losing a daily function now or carrying an exploited remote-execution path until a maintenance window opens.
- precedent With two of the four previously exploited ScreenConnect flaws turning up in ransomware, a KEV listing for this product is a reasonable trigger to treat as pre-ransomware activity from day one.
File transfer and remote execution is the product's job, which is what makes this one hard to spot. CISA said ScreenConnect "contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation" [4]. The check that goes missing is host confirmation. A push into a live session produces the same telemetry as a technician patching a machine, and MSPs use ScreenConnect for exactly that [11]. Turning off TransferFiles permissions, the step ConnectWise published on September 7, removes the capability rather than asking defenders to tell the two apart [2].
Shadowserver counts more than 1,000 unpatched instances reachable online, 758 in North America and 180 in Europe [7]. Those two regions hold 938 of them, about 94 percent of a thousand [12][13]. Because the tracker counts instances still unpatched, a fixed build exists; the TransferFiles change is for servers that have not taken it [15][2]. ConnectWise sells to more than 100,000 IT providers worldwide [11].
The three-day remediation order applies to U.S. federal agencies [3]. The MSPs and in-house IT teams running the rest set their own date, and Shadowserver's count is one measure of what they have set so far [16][7].
This is the fourth ScreenConnect flaw CISA has listed as actively exploited since 2024, and two of the earlier ones were also abused in ransomware attacks [6]. In 2024, the Kimsuky group, which BleepingComputer describes as Korean-backed, and several ransomware gangs exploited CVE-2024-1709 [9]. Both financially motivated and state-backed crews go after ScreenConnect bugs in the wild [8]. CISA said these vulnerability types are "a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise" [5].
BleepingComputer's report does not include a CVE identifier for the newly exploited flaw [14]. The most recent ScreenConnect CVE it names is CVE-2026-3564, a cryptographic signature verification flaw ConnectWise fixed in March that could let attackers hijack unpatched servers [10].
What to watch
- Whether Shadowserver's exposed-and-unpatched count drops below 1,000 once the federal three-day deadline passes.
- A CVE identifier from ConnectWise or CISA for the exploited flaw, so defenders can match it to inventory and scanner output.
- The first named ransomware crew tied to this flaw, following the pattern of two earlier ScreenConnect KEV entries.