
Work Here?
ConnectWise provides a software platform that helps technology service providers manage business operations, remote monitoring, and cybersecurity risk assessments. The platform works by integrating various tools for billing, remote access, and proposal automation into a single ecosystem that connects with hundreds of third-party vendors. Unlike competitors that offer standalone tools, ConnectWise distinguishes itself through a highly integrated suite and a dedicated community called The IT Nation for professional collaboration. The company's goal is to provide a central environment where IT businesses can efficiently manage and scale their service-based models.
Industries
Enterprise Software
Cybersecurity
Company Size
1,001-5,000
Company Stage
Seed
Total Funding
$580K
Headquarters
Tampa, Florida
Founded
1982
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$580k
Below
Industry Average
Funded Over
1 Rounds
Industry standards
Hybrid Work Options
Remote Work Options
Critical ScreenConnect flaw now actively exploited in attacks. Sep 16, 2026 // 14:16 - Niko Dunn Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). ConnectWise shared temporary mitigation measures for this missing-authorization flaw on September 7, advising security teams to disable TransferFiles permissions to block potential attacks. The vulnerability (now tracked as CVE-2026-84869 and patched in ScreenConnect 26.6.5 and later) affects ScreenConnect clients and can let threat actors with basic privileges transfer or execute files in low-complexity attacks that don't require user interaction. CISA added the security flaw to its catalog of actively exploited flaws on Friday and ordered U.S. federal agencies to secure their systems against ongoing attacks within three days. "ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation," CISA said. "These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise." Since 2024, CISA has flagged four ScreenConnect security issues as actively exploited, two of which have also been abused in ransomware attacks. Internet threat watchdog Shadowserver now tracks over 1,000 ScreenConnect instances still unpatched and exposed to attacks online, most of them from North America (758) and Europe (180). ScreenConnect vulnerabilities are often targeted in the wild by both financially-motivated and state-backed hacking groups. For instance, the North Korean-backed Kimsuky hacking group and several ransomware gangs exploited another ScreenConnect flaw (CVE-2024-1709) in 2024. Last year, ConnectWise also rotated digital code-signing certificates after disclosing that suspected state-sponsored hackers breached its systems through code injection attacks that exploited a ViewState flaw (CVE-2025-3935) and accessed the cloud-based instances of a limited number of customers. More recently, in March, ConnectWise addressed a cryptographic signature verification vulnerability (CVE-2026-3564) that could allow attackers to hijack unpatched ScreenConnect servers. ConnectWise provides services to more than 100,000 IT providers worldwide, with many managed service providers (MSPs) and IT teams using its ScreenConnect remote access platform for troubleshooting, patching, and system maintenance.
Critical ScreenConnect flaw now actively exploited in attacks. * September 16, 2026 * 07:14 AM * 0 Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). ConnectWise shared temporary mitigation measures for this missing-authorization flaw on September 7, advising security teams to disable TransferFiles permissions to block potential attacks. The vulnerability (now tracked as CVE-2026-84869 and patched in ScreenConnect 26.6.5 and later) affects ScreenConnect clients and can let threat actors with basic privileges transfer or execute files in low-complexity attacks that don't require user interaction. CISA added the security flaw to its catalog of actively exploited flaws on Friday and ordered U.S. federal agencies to secure their systems against ongoing attacks within three days. "ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation," CISA said. "These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise." Since 2024, CISA has flagged four ScreenConnect security issues as actively exploited, two of which have also been abused in ransomware attacks. Internet threat watchdog Shadowserver now tracks over 1,000 ScreenConnect instances still unpatched and exposed to attacks online, most of them from North America (758) and Europe (180). ScreenConnect vulnerabilities are often targeted in the wild by both financially-motivated and state-backed hacking groups. For instance, the North Korean-backed Kimsuky hacking group and several ransomware gangs exploited another ScreenConnect flaw (CVE-2024-1709) in 2024. Last year, ConnectWise also rotated digital code-signing certificates after disclosing that suspected state-sponsored hackers breached its systems through code injection attacks that exploited a ViewState flaw (CVE-2025-3935) and accessed the cloud-based instances of a limited number of customers. More recently, in March, ConnectWise addressed a cryptographic signature verification vulnerability (CVE-2026-3564) that could allow attackers to hijack unpatched ScreenConnect servers. ConnectWise provides services to more than 100,000 IT providers worldwide, with many managed service providers (MSPs) and IT teams using its ScreenConnect remote access platform for troubleshooting, patching, and system maintenance. Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
ScreenConnect flaw under attack, patch urged. CISA orders federal agencies to fix a critical ConnectWise ScreenConnect flaw exploited in the wild, with over 1,000 instances still exposed. CVE-2026-84869 critical Actively exploited A critical authorization flaw in ConnectWise's ScreenConnect remote access tool is now being exploited in live attacks, prompting the U.S. Cybersecurity and Infrastructure Security Agency to add it to its catalog of actively exploited flaws and give federal agencies three days to secure their systems. The bug, tracked as CVE-2026-84869, lets attackers with only basic privileges move and run files on vulnerable servers, and more than a thousand internet-facing instances remain unpatched. What the flaw allows. According to CISA, the vulnerability combines two distinct weaknesses: improper privilege management and missing authorization. Together they may let an attacker transfer and execute files through an active remote session without the host's authorization or confirmation. That means the victim does not need to click anything or approve a prompt - the session itself becomes the delivery path. The agency describes the attack complexity as low and notes that no user interaction is required. An adversary who already holds basic privileges on a ScreenConnect instance can leverage the flaw to push files onto the target and run them. ConnectWise patched the issue in ScreenConnect version 26.6.5 and later. Three-Day deadline for federal agencies. CISA added the flaw to its catalog of actively exploited vulnerabilities on Friday and ordered U.S. federal agencies to secure their systems against ongoing attacks within three days. That timetable is among the shortest the agency applies, reserved for bugs it believes are being used right now against real targets. The agency framed the risk in stark terms: "ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation," CISA said. "These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise." - CISA, U.S. Cybersecurity and Infrastructure Security Agency Interim mitigation before patching. Before a patch was available, ConnectWise shared temporary mitigation measures on September 7, advising security teams to disable TransferFiles permissions to block potential attacks. That step removes the file-transfer capability the flaw depends on, cutting off the most direct exploitation path while administrators prepare to upgrade. Organizations that have not yet applied the fix should treat the TransferFiles change as a stopgap, not a permanent solution. Upgrading to ScreenConnect 26.6.5 or later restores full functionality while closing the underlying authorization gap. Over 1,000 exposed instances. Internet threat watchdog Shadowserver now tracks over 1,000 ScreenConnect instances that remain unpatched and exposed online, according to the source. The geographic breakdown shows most of the vulnerable systems are in North America (758), followed by Europe (180). Those figures matter because ScreenConnect is widely deployed by managed service providers and IT teams for troubleshooting, patching and remote maintenance. An exposed instance is not just a single company's problem - it can be a foothold into every customer that relies on that provider. A repeated target for attackers. ScreenConnect vulnerabilities are often targeted in the wild by both financially motivated and state-backed hacking groups. Since 2024, CISA has flagged four ScreenConnect security issues as actively exploited, two of which have also been abused in ransomware attacks. The North Korean-backed Kimsuky hacking group and several ransomware gangs exploited another ScreenConnect flaw, CVE-2024-1709, in 2024. That history shows the platform sits on a shortlist of remote-access tools that attackers return to whenever a new weakness appears. Earlier breaches and certificate rotation. Last year, ConnectWise rotated digital code-signing certificates after disclosing that suspected state-sponsored hackers breached its systems through code injection attacks that exploited a ViewState flaw (CVE-2025-3935) and accessed the cloud-based instances of a limited number of customers. More recently, in March, ConnectWise addressed a cryptographic signature verification vulnerability (CVE-2026-3564) that could allow attackers to hijack unpatched ScreenConnect servers. The pattern of repeated fixes is part of why CISA treats each new ScreenConnect flaw as urgent rather than routine. Scale of the ScreenConnect Footprint. ConnectWise provides services to more than 100,000 IT providers worldwide, with many managed service providers and IT teams using its ScreenConnect remote access platform for troubleshooting, patching and system maintenance. That reach explains why a single authorization flaw can ripple across thousands of downstream organizations. For MSPs, the exposure is twofold: their own infrastructure may be vulnerable, and their clients' environments may be reachable through a compromised management session. The Shadowserver data on unpatched instances is a direct measure of how much of that surface remains open. Key figures behind the alert. * CVE-2026-84869 - the critical ScreenConnect flaw now exploited in the wild * 26.6.5 - the ScreenConnect version that fixes the issue and later * September 7 - date ConnectWise shared temporary mitigation measures * Three days - deadline CISA gave federal agencies to secure systems * Over 1,000 - ScreenConnect instances still unpatched and exposed, per Shadowserver * 758 - exposed instances in North America; 180 in Europe * Four - ScreenConnect issues CISA has flagged as actively exploited since 2024 * 100,000+ - IT providers worldwide served by ConnectWise What patching and mitigation demand. Security teams running ScreenConnect should verify their version and move to 26.6.5 or later as soon as possible. Where an upgrade cannot be completed immediately, disabling TransferFiles permissions remains the recommended interim step, according to ConnectWise's September 7 guidance. Because the flaw requires no user interaction, defenders cannot rely on employee awareness training to stop it. The window for action is set by CISA's three-day directive for federal agencies, and the Shadowserver tally shows a substantial number of organizations outside that mandate are still exposed. Why This matters beyond federal networks. The three-day order applies to U.S. federal agencies, but the vulnerable software is used far more widely by MSPs and private IT teams. A flaw that lets attackers transfer and execute files through an active session can turn a trusted remote-support channel into a delivery mechanism, and the Shadowserver count of over 1,000 exposed instances suggests many organizations have not yet acted. This could mean that the most immediate risk sits with smaller providers and their clients, who may lack the staff to track CISA catalog updates or ConnectWise advisories in real time. The repeated history of ScreenConnect exploitation - four flagged issues since 2024, including CVE-2024-1709 used by Kimsuky and ransomware gangs - suggests attackers already know where to look. For MSPs, the practical takeaway is to inventory ScreenConnect deployments, confirm patch levels, and treat any internet-facing instance that has not been updated as an active liability rather than a pending ticket. The source material does not indicate how many of the exposed instances belong to federal agencies versus private operators, so the true scope of ongoing exploitation remains unclear. #screenconnect #cisa #connectwise #vulnerability #remote access #exploitation Founder & Editor, Xploitwire This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read its Editorial Policy
ConnectWise patches critical ScreenConnect authentication failure after five days. ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation. The company warned customers on Sept. 3 of the problem with support and access sessions in ConnectWise Remote Access, advising admins to log in and remove the "TransferFiles" permission from any users with an open session. Last month ConnectWise took the opportunity to reassure customers at its IT Nation Connect Asia Pacific conference that it was getting back on track after a "nation-state attack" in May 2025 that had affected several customers. The company quickly released a patch for that attack and said no customers had suffered loss. This was not the first time that the company had suffered from a cyberattack. In 2024, ConnectWise had to issue a patch after reports that ScreenConnect had been exploited. ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation. The company warned customers on Sept. 3 of the problem with support and access sessions in ConnectWise Remote Access, advising admins to log in and remove the "TransferFiles" permission from any users with an open session. Last month ConnectWise took the opportunity to reassure customers at its IT Nation Connect Asia Pacific conference that it was getting back on track after a "nation-state attack" in May 2025 that had affected several customers. The company quickly released a patch for that attack and said no customers had suffered loss. This was not the first time that the company had suffered from a cyberattack. In 2024, ConnectWise had to issue a patch after reports that ScreenConnect had been exploited.
Hackers turn ScreenConnect into its own infection vector in new worm-like campaign. 2026-09-08 19:09 A remote access tool built for IT departments and help desks is now being weaponized against them. Researchers at Huntress say they've found hacked versions of ConnectWise's ScreenConnect software that don't just give attackers a foothold on one machine, they use that foothold to infect whoever connects to it next, turning a single compromised endpoint into a launching pad for further attacks. Huntress said its Security Operations Center issued three critical incident alerts in late August after spotting the same unusual pattern across customer networks that had nothing else in common. In each case, a rogue ScreenConnect client had been planted through social engineering, and once running, it began quietly automating an infection chain that most victims never saw coming. Three break-ins, one playbook Hacking & Cracking The entry points varied, but the outcome didn't. On August 20, Huntress caught a case that started with a classic tech support scam: someone called a victim claiming their computer had been hacked, then walked them through opening Quick Assist, the remote help tool that ships with Windows, and handing over control. Once inside, the attacker installed a ScreenConnect client wired to call home to a server at 45.13.237[.]190, an address that VirusTotal had tied to a domain called tele-sync.opik[.]net earlier that same month. A second incident, logged the same day, took a different path in. The victim ran a file called ScreenConnect.ClientSetup.msi straight out of a Microsoft Edge downloads folder, almost certainly after clicking through a phishing email. That installer set up a client pointed at a separate server, 131.123.40[.]98, over port 8041. Huntress later found the same machine reaching out to several more IP addresses tied to the campaign's infrastructure. The third case, on August 24, started with something almost mundane: a person searching online for a Geek Squad refund form. Instead of a form, they got a rogue ScreenConnect.Client.exe that connected back to a domain named borertors92.anondns[.]net. Huntress shut this one down quickly enough that it never progressed past the initial script execution. Different bait, same result. Once the ScreenConnect client landed on a machine, it began repeatedly calling wscript.exe, the built-in Windows scripting engine, to fire off four files named, plainly, 1.vbs, 2.vbs, 3.vbs and 4.vbs. What the four scripts actually do Huntress pulled the scripts apart and found a loader designed to feel its way around a system before deciding what to drop on it. The first script checks whether ScreenConnect is already installed, looks for security software including Huntress's own agent, CrowdStrike, SentinelOne, Sophos, Malwarebytes and Cisco AMP, and checks how much memory the machine has, likely a crude way of ruling out sandboxes and virtual machines used by researchers. It boils all of that down into a three-digit code and drops it into a file called value.txt in the Windows temp folder. The second script waits for that file to appear, then fetches a link from Dropbox, decodes it and stores the result as a lookup table. Each possible three-digit combination in that table maps to a different payload and a different AES decryption key. The third script reads the table, matches it against the code generated earlier, and downloads whichever payload fits. The fourth script grabs the matching decryption key, builds a PowerShell script from scratch inside the VBScript itself, and runs it with Windows' script execution safeguards switched off. Antivirus & Malware That PowerShell script does the actual unwrapping, decrypting the downloaded file and handing control to a second, more capable PowerShell script that Huntress found renamed as PyTorchFix.ps1. Depending on which of the three outcomes the profiling scripts settled on, the victim ends up with either a bare-bones backdoored ScreenConnect client, a version bundled with tools for privilege escalation and persistence, or the full package: tunneling software and a cryptocurrency miner thrown in as well. One small detail stood out to the researchers. A comment buried in the third script spells out the payload table's format in plain, tutorial-style language, the kind of explanatory note that reads less like something a human attacker jotted down and more like something an AI coding tool generated on the fly. How the infection spreads on its own This is the part that makes the campaign unusual. Buried in the backdoored ScreenConnect client is code that watches ScreenConnect's own connection list for new sessions. The moment somebody new connects, whether that's another victim, a technician, or anyone else routed through the same infrastructure, the client repackages all four VBScript files, hands them to ScreenConnect's built-in file transfer feature, flags them to run automatically, and pushes them straight to the new arrival. Huntress described it as the modified client using the server's own connection status data to figure out who just showed up, then quietly [...] Content was trimmed to protect the source. Please visit the original article for the full text. Discover more Dictionaries & Encyclopedias Read the original article: A security alert now circulates among ScreenConnect users - critical exposure lurks within older builds. Versions released before 26.1 carry a defect labeled CVE-2026-3564. Unauthorized entry becomes possible through this gap, alongside elevated permissions. ConnectWise urges immediate awareness around these risks. Though no widespread attacks appear confirmed yet, the potential... Security Products & Services March 28, 2026 In "CySecurity News - Latest Information Security and Hacking Incidents" A new phishing campaign is taking advantage of concerns over a recently revealed COLDCARD wallet vulnerability and the suspected theft of $88.6 million in... August 23, 2026 In "CySecurity News - Latest Information Security and Hacking Incidents" Shortly after reports emerged regarding a significant security flaw in the ConnectWise ScreenConnect remote desktop management service, researchers are sounding the alarm about a potential large-scale supply chain attack.Kyle Hanslovan, CEO of Huntress, expressed concerns about the exploitation of these vulnerabilities, warning that hackers could potentially infiltrate thousands of... February 26, 2024 In "CySecurity News - Latest Information Security and Hacking Incidents"
Find jobs on Simplify and start your career today
Industries
Enterprise Software
Cybersecurity
Company Size
1,001-5,000
Company Stage
Seed
Total Funding
$580K
Headquarters
Tampa, Florida
Founded
1982
Find jobs on Simplify and start your career today