ConnectWise, Races

ConnectWise Races to Patch ScreenConnect File-Transfer Flaw as Researchers Uncover Malware Campaign

Published on 09/10/2026 at 06:20 | Editorial boerse-global.de

ConnectWise warned of an unpatched ScreenConnect file-transfer flaw as researchers traced a four-stage VBScript chain pushed via remote sessions.

ConnectWise ScreenConnect Flaws: File-Transfer Gap and Attack Chain
ConnectWise Races to Patch ScreenConnect File-Transfer Flaw as Researchers Uncover Malware Campaign Illustration mit AI erstellt.

Administrators running ConnectWise's ScreenConnect remote-access tool have had a busy few months. A critical vulnerability patched in March 2026 has been followed by fresh warnings over the summer, and security researchers are now piecing together how attackers have been abusing the platform to push malicious code onto connected machines.

A file-transfer gap with no patch — yet

At the start of September 2026, ConnectWise alerted customers to a security issue affecting file transfers within ScreenConnect. Both cloud and on-premises installations are in scope, according to the company.

No software fix was ready when the first advisories went out. ConnectWise said a patch was expected in the week beginning 07.09.2026. The flaw has not been assigned a CVE identifier so far.

In the meantime, the vendor told administrators to tighten permissions inside the product. The recommended step: go to Administration > Security > Roles and strip out the "TransferFiles" right. On older builds, that same permission appears under the name "TransferFilesInSession."

Four-stage script chain delivered through legitimate remote sessions

Researchers at Huntress flagged incidents in August 2026 in which intruders turned ScreenConnect instances into a delivery mechanism for malicious code. A four-part VBScript chain — files named 1.vbs through 4.vbs — was pushed to machines as they connected.

The attackers appear to have relied on modified ScreenConnect clients and the product's ordinary remote-access workflow, a technique that makes detection harder inside managed environments.

How much damage the campaign did varied with the endpoint protection installed on target systems. Products from Cisco AMP, CrowdStrike, Huntress, Malwarebytes, SentinelOne, Sophos and Symantec were all named in this connection. Whether these attacks are technically linked to the file-transfer weakness disclosed in early September has not been established.

The March flaw that set the tone

Context for assessing the platform's overall security posture comes from CVE-2026-3564, a vulnerability rated 9.0 on the CVSS scale — squarely in critical territory. It allowed ASP.NET Machine Keys to be extracted, opening the door to session hijacking and privilege escalation.

Only on-premises ScreenConnect deployments running versions below 26.1 were affected. A patch landed on 18.03.2026. Cloud instances were shielded automatically by the vendor, while operators of self-hosted servers had to apply the update themselves. As of September 2026, there had been no reports of active exploitation of this particular flaw.

Thousands of instances still reachable from the open internet

Even with older patches in place, remote-access tools present a wide attack surface. Shadowserver data shows roughly 6,000 ScreenConnect instances exposed online.

IT teams are being urged to review their configurations on a regular basis and to keep file-transfer permissions as tight as possible until final security updates for the most recent disclosures are in place.

Security professionals are also pointing to CVE-2024-1709, a 2024 vulnerability, as a historical reference point for the current situation.

Disclaimer...

en | boerse | 70079012 |