ConnectWise ScreenConnect Hit by New File-Transfer Flaw, Patch Days Away
The remote-support tool used by IT teams worldwide has a bug that lets attackers move files through active sessions. A fix is expected this week.

Key points
- ConnectWise disclosed a new flaw in ScreenConnect on Thursday affecting file transfer in Remote Access and Support sessions, with a patch expected later in the week.
- The bug has no CVE identifier yet and hits both cloud and on-premises installations.
- Roughly 6,000 ScreenConnect servers sit exposed on the public internet, according to scans by the Shadowserver Foundation.
- ConnectWise's workaround tells administrators to strip the TransferFiles permission from user roles until the fix lands.
- Past ScreenConnect bugs have been used by ransomware crews and North Korea's Kimsuky group, and three sit on the U.S. government's known-exploited list.
ConnectWise is telling customers to disable file transfers inside its ScreenConnect remote-support tool while it finishes work on a patch due later this week.
ScreenConnect, sold to managed service providers and corporate IT teams, lets a technician take control of a distant computer to fix problems, install updates, or move files. It runs either in ConnectWise's cloud or on a customer's own server. Both setups are affected.
The company published a security advisory on Thursday describing "an issue affecting file transfer behavior" in active sessions. It has not assigned a CVE tracking number, and it has not said whether anyone is exploiting the bug yet.
First reported by BleepingComputer, the disclosure is short on technical detail. What ConnectWise did publish is a workaround.
What should IT teams do right now?
Strip file-transfer rights from every ScreenConnect role until the patch arrives. That is the mitigation ConnectWise is asking for, and it can be done from the admin console in a few minutes.
The steps: log into the ScreenConnect Administration page, open Administration then Security then Roles, edit each role, and untick the TransferFiles permission (called TransferFilesInSession on older builds) inside Scoped Permissions. Save, then repeat for every role. Technicians will still be able to open remote sessions. They just will not be able to push or pull files through them.
How exposed is the wider internet?
The Shadowserver Foundation, a non-profit that scans the internet for exposed systems, currently sees close to 6,000 ScreenConnect servers reachable from the public internet. Not all of those are vulnerable, and some will be honeypots (decoy systems set up by researchers to bait attackers). But the number is a fair proxy for how much attack surface is out there.
Why does this product keep getting attacked?
Remote-support software is a shortcut into everything a company owns. Break one ScreenConnect server and you can potentially reach every machine it manages, which is why criminal and government hackers keep going after it.
In 2024, ransomware gangs and North Korea's Kimsuky spying group exploited a different ScreenConnect flaw, CVE-2024-1709, an authentication bypass that let anyone create an admin account on an unpatched server. Earlier this year ConnectWise itself was breached through a separate bug, CVE-2025-3935, which the company blamed on a suspected state-backed group. A cryptographic signature bug patched in March, tracked as CVE-2025-3564, added to the run.
The U.S. Cybersecurity and Infrastructure Security Agency has added three ScreenConnect flaws to its Known Exploited Vulnerabilities catalogue since February 2024. Two were used in ransomware campaigns.
Recent ScreenConnect security history
| Date | Issue | Notes |
|---|---|---|
| Feb 2024 | CVE-2024-1709 | Auth bypass, used by ransomware crews and Kimsuky |
| Mar 2025 | CVE-2025-3564 | Signature verification bug, patched |
| 2025 | CVE-2025-3935 | ViewState injection, used to breach ConnectWise cloud |
| Nov 2025 | New file-transfer flaw | No CVE yet, patch pending, workaround available |
Should ordinary customers be worried?
If your employer, accountant, or IT provider uses ScreenConnect to support your machine, the fix is on their side, not yours. Watch for support sessions you did not request, and hang up on anyone who cold-calls claiming to be from IT and asks you to approve a remote connection. That has always been good practice. This week it matters more.



