Security Intelligence
September 9, 2026 | Security intelligence
ScreenConnect vulnerability disclosed following worm-like malware campaign
At a glance:
-
ConnectWise disclosed a ScreenConnect security issue affecting file transfer behavior on September 3, 2026, and released mitigations while a patch is being developed.
-
Modified ScreenConnect clients were seen spreading malicious payloads to newly connected endpoints through ScreenConnect sessions in multiple organizations during August 2026.
-
Publicly available information suggests the two events may be related, although ConnectWise has not confirmed that the disclosed vulnerability was used in the activity observed.
Threat summary
On September 3, ConnectWise disclosed a security issue affecting file transfer functionality in ScreenConnect Remote Access Support and Access sessions. The issue affects both cloud-hosted and on-premises deployments.
ConnectWise released interim mitigation guidance, advising customers to temporarily disable file transfer permissions while developing a patch and assigning a Common Vulnerabilities and Exposures (CVE) identifier.
ScreenConnect is a remote access and remote support platform used to manage endpoints, transfer files, troubleshoot systems, and provide unattended administrative access. The platform is widely deployed in enterprise environments and enables administrators to interact directly with remote systems through persistent access agents.
The disclosure comes after researchers reported a series of compromises affecting multiple unrelated organizations. Beginning in August 2026, threat actors used social engineering techniques, including Quick Assist tech-support scams, phishing-delivered installers, and fraudulent support or refund lures, to install rogue ScreenConnect clients on victim systems.
Once installed, the modified clients repeatedly spawned wscript.exe to execute a four-stage VBScript chain consisting of 1.vbs, 2.vbs, 3.vbs, and 4.vbs. The scripts performed host reconnaissance, enumerated installed security products, staged additional payloads, executed PowerShell commands, and established persistence through a WindowsServiceHost registry Run key.
Researchers found that the modified ScreenConnect clients automatically transferred and executed the same payloads on newly connected endpoints. This propagation mechanism allowed malicious files to spread from the initially compromised system to additional managed devices through trusted remote management infrastructure. Researchers also observed installation of remote access tools such as UltraViewer, communications with attacker-controlled infrastructure, attempts to bypass User Account Control (UAC), and deployment of concealed ScreenConnect clients designed to maintain access and continue propagation.
ConnectWise has not linked the disclosed issue to the activity documented by researchers.
Analysis
ConnectWise has not linked the disclosed issue to the activity documented by researchers. However, several factors suggest the disclosure and the reported campaign may be related. Following discussions with researchers investigating the incidents, ConnectWise disclosed a security issue affecting file transfer functionality and advised customers to disable file transfer permissions until a fix becomes available.
The activity is notable because ScreenConnect has a history of attracting threat actor interest. In 2024, threat actors widely exploited CVE-2024-1709, a critical authentication bypass vulnerability that affected self-hosted ScreenConnect servers and enabled remote code execution. The vulnerability was subsequently added to CISA's Known Exploited Vulnerabilities catalog, and multiple ransomware operators incorporated it into their operations. As a result, many organizations continue to view ScreenConnect as a high-value target due to its privileged access to managed systems.
Organizations operating ScreenConnect deployments face the greatest risk. The primary concern is the ability of a compromised ScreenConnect instance to distribute files and execute actions across additional managed systems. ScreenConnect is commonly deployed with broad administrative access to workstations and servers, allowing activity originating from a single compromised instance to reach numerous endpoints. In managed service provider environments, that access may extend across multiple customer networks, increasing the potential impact of a compromise. Environments with self-hosted ScreenConnect deployments, file transfer permissions enabled, and broad endpoint access present the highest operational risk if similar activity occurs.
If the observed propagation activity can be replicated through the newly disclosed issue, a successful compromise could provide an effective mechanism for distributing malicious files, establishing persistence, and expanding access across connected systems using trusted administrative infrastructure.
Even in scenarios where the activity relies solely on legitimate product functionality, a compromised ScreenConnect environment would remain a significant operational risk because attackers could leverage existing administrative access and file transfer capabilities to move laterally and deploy payloads at scale.
Mitigations
Asset identification efforts should focus on locating all ScreenConnect deployments, particularly self-hosted instances, and identifying which systems have administrative access to managed endpoints. Organizations should inventory ScreenConnect servers, review installed agents, and verify which administrators and service accounts have access to file transfer and remote execution functions.
Until ConnectWise releases a patched version, organizations should review role permissions and remove the TransferFiles and TransferFilesInSession permissions wherever operational requirements allow. Restricting file transfer capabilities reduces the ability of a compromised account or ScreenConnect instance to distribute payloads to additional managed systems.
Organizations that require file transfer functionality for ongoing operations should limit access to a small number of trusted administrative accounts, review permission assignments regularly, remove unnecessary or inactive accounts, and closely monitor file transfer activity.
Monitoring efforts should focus on ScreenConnect audit logs for unexpected file transfer activity, RunFiles or RanFiles events, transfers originating from unfamiliar administrator accounts, large numbers of file transfers across multiple endpoints, and file deployment activity outside of normal maintenance windows.
Organizations should also monitor endpoint telemetry for repeated execution of wscript.exe, deployment of 1.vbs through 4.vbs, creation of the WindowsServiceHost persistence mechanism documented during the investigation, unusual PowerShell execution, and the installation of previously unseen remote access tools.
Hunting activities should include reviewing ScreenConnect administrative accounts, validating recent permission changes, examining newly connected endpoints, and identifying systems that received files through ScreenConnect during the period of concern. Any unexpected file transfers or remote execution activity should be investigated to determine whether the activity originated from authorized administrative actions.
Network and security teams should ensure that ScreenConnect servers are fully patched against previously disclosed vulnerabilities and that access to the administrative interface is restricted to trusted management networks wherever possible. Multi-factor authentication should be enforced for administrative accounts to further reduce the likelihood of unauthorized access.
Once ConnectWise releases a patched version, organizations should prioritize updating the Internet-facing and self-hosted ScreenConnect servers, followed by internally accessible systems. After updating, teams should confirm that the update was successfully applied, review role permissions that were temporarily modified during mitigation efforts, and continue monitoring for abnormal file transfer activity to identify any signs of prior compromise.
Stay on top of emerging threats like this.
Sign up to receive a weekly roundup of our security intelligence feed. You'll be the first to know of emerging attack vectors, threats, and vulnerabilities.

