ConnectWise has warned customers about a newly discovered security issue involving file transfers in ScreenConnect Remote Access.
The issue affects both cloud-based and self-hosted deployments. ConnectWise has provided temporary mitigation steps while it works on a permanent fix.
The advisory was published on September 3, 2026. A CVE number and official security update are expected after the cloud-side changes are completed.
ScreenConnect File Transfer Issue
The vulnerability affects Support and Access sessions in CW Remote Access, previously known as ScreenConnect.
ConnectWise has not yet shared detailed technical information about the flaw or confirmed whether attackers have exploited it in real-world attacks.
However, the company recommends that administrators take action now because remote-access platforms can provide access to company devices and sensitive environments.
ConnectWise Recommends Disabling File Transfers
Until the permanent fix is available, organizations should restrict technician file-transfer permissions.
Administrators can make this change without upgrading ScreenConnect.
The recommended steps are:
- Log in to the ScreenConnect Administration page.
- Go to Administration > Security > Roles.
- Review each role assigned to ScreenConnect users.
- Check the relevant session groups and open Scoped Permissions.
- Disable
TransferFiles. - On older versions, also check for
TransferFilesInSession. - Save the changes.
- Repeat the process for all configured roles.
Disabling these permissions may affect support teams that regularly transfer files during remote sessions, but it can reduce exposure while the permanent fix is being prepared.
What Organizations Should Do
Security teams should also:
- Review ScreenConnect administrator accounts.
- Remove unnecessary privileged access.
- Check user roles and permissions.
- Monitor unusual remote-access activity.
- Watch for unexpected file-transfer attempts.
- Follow ConnectWise advisories for the official patch and CVE details.
Final Thoughts
Remote-access tools are valuable for IT teams, but they can also become attractive targets for attackers. Until ConnectWise releases the permanent fix, organizations using ScreenConnect should review their permissions and disable unnecessary file-transfer capabilities.
Regularly reviewing remote-access privileges can help reduce the impact of vulnerabilities before they become security incidents.