Who is affected
ConnectWise ScreenConnect is a remote access and support tool widely deployed in IT service organisations, managed service providers, and corporate support teams. The vulnerability allows an attacker to perform file transfer and code execution through an active remote session without requiring authorisation from the user or host operator. The record does not specify which versions of ScreenConnect are vulnerable or whether cloud-hosted versus self-hosted deployments carry different risk.
How to check whether this touches you
- Search your asset inventory and procurement records for ConnectWise ScreenConnect installations, including both on-premises deployments and any use of ConnectWise's cloud-hosted service.
- Identify which ScreenConnect instances are reachable from the internet or from untrusted networks; these carry the highest risk of exploitation.
- Note the current build number of each deployment by accessing the ScreenConnect console or agent properties; vendor patch announcements will specify affected build ranges, and version strings alone do not confirm whether a backported fix has been applied.
- Review access logs to identify which remote sessions have been active and from which source addresses, as this will inform your retrospective investigation scope.
What to do
- Immediately obtain the vendor's official advisory and patch guidance from ConnectWise, including the specific build versions that address this vulnerability.
- Assess internet-facing ScreenConnect instances as your priority; if any are exposed without additional network controls, consider temporarily restricting access to known-good source addresses or requiring VPN transit.
- Apply the vendor's mitigations in accordance with CISA BOD 26-04 timelines; if your organisation is federal or operates critical infrastructure, the remediation due date is 14 September 2026.
- If patching cannot be completed within the required timeframe, evaluate whether discontinuing use of unpatched instances is feasible for your operational model.
- Enable and retain detailed logging of all file transfers and command execution events within ScreenConnect, and configure alerting for any transfer or execution activity that lacks corresponding user interaction records.
- Escalate to your security operations and incident response teams if you cannot patch or mitigate within the deadline, or if you discover evidence of unauthorised file transfer or execution during active sessions.
If you find you were exposed
Exploitation typically precedes public disclosure by weeks or months, so hunt backwards from the disclosure date using your session logs, file transfer records, and endpoint execution histories. Cross-reference any remote sessions that lack explicit user authorisation with corresponding file system and process creation events on the affected hosts. Log retention policies are your constraint; if you retain fewer than 90 days of ScreenConnect session data, you may be unable to confirm retrospective compromise.