ConnectWise ScreenConnect file-transfer mitigation advisory
Advisory/Mitigation
Summary
Hide ▲
Show ▼
ConnectWise issued a ScreenConnect mitigation advisory after identifying an issue affecting file transfer behavior in Remote Access Support and Access sessions. The guidance applies to both Cloud and On-Premise deployments and tells customers to disable technician file transfer permissions until a fix is available. The recommended change reduces the risk of unwanted file movement through affected sessions.
Related Happenings
ConnectWise ScreenConnect Remote Access file-transfer mitigation
Advisory/Mitigation
H score57
First: 07.09.2026 13:06
Last: 07.09.2026 13:06
Sources 1
About this happening:
ConnectWise issued temporary mitigation steps for a ScreenConnect Remote Access file-transfer flaw affecting cloud and on-premises deployments. Administrators are...
ConnectWise ScreenConnect Remote Access file-transfer mitigation
Advisory/MitigationAbout this happening: ConnectWise issued temporary mitigation steps for a ScreenConnect Remote Access file-transfer flaw affecting cloud and on-premises deployments. Administrators are...
ScreenConnect Remote Access file-transfer security flaw
Vulnerability
H score48
First: 07.09.2026 13:06
Last: 07.09.2026 13:06
Sources 1
About this happening:
The ScreenConnect Remote Access file-transfer vulnerability affects cloud and on-premises deployments and puts Support and Access sessions at risk. ConnectWise has...
ScreenConnect Remote Access file-transfer security flaw
VulnerabilityAbout this happening: The ScreenConnect Remote Access file-transfer vulnerability affects cloud and on-premises deployments and puts Support and Access sessions at risk. ConnectWise has...
StormEncryptor ransomware deployment by Storm-1175
Malware Activity
H score40
First: 10.08.2026 20:42
Last: 10.08.2026 20:42
Sources 1
About this happening:
Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ran...
StormEncryptor ransomware deployment by Storm-1175
Malware ActivityAbout this happening: Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ran...
ConnectWise ScreenConnect remote access installation chain
Malware Activity
H score29
First: 05.08.2026 20:49
Last: 05.08.2026 20:49
Sources 1
About this happening:
A malicious installer chain is now deploying ConnectWise ScreenConnect through a batch file and setup.msi, giving operators remote access to victim devices. The pa...
ConnectWise ScreenConnect remote access installation chain
Malware ActivityAbout this happening: A malicious installer chain is now deploying ConnectWise ScreenConnect through a batch file and setup.msi, giving operators remote access to victim devices. The pa...
N-able security patch release for CVE-2026-18577
Security Patch Release
H score46
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
N-able security patch release for CVE-2026-18577
Security Patch ReleaseAbout this happening: N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
Timeline
-
07.09.2026 14:36 2 articles · 3h ago
ConnectWise issues ScreenConnect file-transfer mitigation advisory
Mitigation Patch UpdateConnectWise issued an advisory for ScreenConnect Remote Access Support and Access sessions after identifying an issue affecting file transfer behavior across Cloud and On-Premise deployments, and recommended disabling technician file-transfer permissions until a fix is available.
Show sources
- Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts — thehackernews.com — 07.09.2026 14:36
- Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts — thehackernews.com — 07.09.2026 14:36