ConnectWise has issued a warning regarding a newly discovered security vulnerability impacting the file transfer functionality within ScreenConnect Remote Access Support and Access sessions. This issue affects both cloud-hosted and self-hosted ScreenConnect solutions.
Security Advisory Details
The advisory, which was made public on September 3, 2026, lacks a CVE identifier at this stage. However, ConnectWise expects to provide a CVE and a formal patch within a week, following the updates to their cloud environments. This vulnerability is related to ScreenConnect, now known as CW Remote Access, and specifically pertains to Support and Access sessions.
ConnectWise has not yet revealed specific technical details regarding how the file transfer function can be exploited, nor have they indicated if there have been any known attacks utilizing this vulnerability. Nonetheless, the company is urging administrators and partners to take immediate precautions by limiting file-transfer capabilities for technicians.
Mitigation Measures
In response to this issue, ConnectWise has rolled out interim mitigation strategies applicable to ScreenConnect Remote Access instances operating under both its cloud infrastructure and self-hosted configurations. Organizations relying on ScreenConnect for remote support are advised to reassess user roles, session groups, and permissions related to file transfers across their systems.
Administrators should navigate to the ScreenConnect Administration page to access the Security and Roles section. Here, they must examine all roles and session groups to verify if file transfer permissions such as TransferFiles or TransferFilesInSession are enabled. If these permissions are active, they should be removed to mitigate the risk of exploitation.
Future Outlook
ConnectWise is actively working on a comprehensive fix for this file-transfer behavior flaw. The company plans to release further guidance once the update is available and will assign a CVE identifier post-cloud deployment. Organizations are encouraged to keep a close watch on the ConnectWise advisory page for information on the official patch, CVE details, and any new detection or response strategies.
Additionally, security teams should routinely review administrative accounts, ensuring only authorized personnel hold privileged roles, and monitor for unusual file-transfer activities or unexpected modifications to permissions within remote-support sessions.
