VulnerabilityBleeping Computer
10.0 — CRITICAL
ConnectWise warns of new ScreenConnect flaw without patch
ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A new ScreenConnect Remote Access vulnerability has been identified, affecting both cloud and on-premises deployments, with potential attacks targeted by financially-motivated and state-backed hacking groups.
⚙️Technical Details
CVEs
CVE-2024-1709CVE-2025-3935CVE-2026-3564Affected Systems: Connectwise Screenconnect
Affected Systems
Connectwise Screenconnect
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Managed service providers (MSPs), IT departments, and support teams using ScreenConnect Remote Access
🛡️Recommended Actions
1Log in to the ScreenConnect Administration page and edit user roles to deselect TransferFiles permission for each session group.
2Save changes and repeat for all roles.
3Implement temporary mitigation steps provided by ConnectWise to block potential attacks.
📦Affected Products
Connectwise Screenconnect
🔐NVD Verified DataVERIFIED
CVE-2024-1709 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-288
Affected Products (CPE)
Connectwise Screenconnect
CVE-2025-3935 ↗CVSS 7.2 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-502
Affected Products (CPE)
Connectwise Screenconnect
CVE-2026-3564 ↗CVSS 9 — CRITICAL
Attack Vector
NETWORK
Complexity
HIGH
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-347
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
