ConnectWise Wants You to Disable File Transfers Before the Patch Exists
- The Mess: ConnectWise has disclosed a new ScreenConnect security issue affecting file-transfer behavior in Remote Access Support and Access sessions.
The problem affects both Cloud and On-Premise deployments.
There is no CVE yet.
There was no full patch available when ConnectWise issued the advisory.
Instead, administrators were told to do something blunt: disable file transfers until the permanent fix arrives.
- The Damage: ScreenConnect is remote-access infrastructure. A problem involving file movement inside privileged remote sessions deserves attention even before the vendor publishes the full technical details.
ConnectWise has not disclosed the root cause, affected version range, exploitation requirements or whether attackers are already abusing this specific flaw.
That leaves defenders making decisions with incomplete information.
The interim mitigation requires administrators to remove the TransferFiles permission — or TransferFilesInSession on legacy deployments — from relevant ScreenConnect roles.
In other words, if you want the temporary protection, you may have to break a feature your support teams actually use.
ScreenConnect is also not some obscure remote-support tool sitting in a forgotten corner of the Internet. Security researchers have repeatedly seen ransomware crews and state-linked operators target vulnerabilities in the platform.
Remote-management software has privileged access by design.
When something goes wrong, the blast radius can include every endpoint the platform can reach.
- The Fix: Disable file-transfer permissions where possible, inventory both cloud and self-hosted ScreenConnect deployments, and prepare to deploy ConnectWise’s official update as soon as it becomes available.
Also review ScreenConnect activity and recent file transfers for anything unusual.
ConnectWise says a CVE identifier and official fix are expected within the week.
Bugstoday’s Opinion
This is the uncomfortable version of patch management.
There is a security problem.
The vendor hasn’t explained exactly how it works.
The permanent patch isn’t ready.
So the temporary answer is:
Turn off part of the product.
Maybe the flaw turns out to be difficult to exploit.
Maybe it doesn’t.
But ScreenConnect is exactly the kind of infrastructure where defenders should not wait for a full technical postmortem before paying attention.
A remote-access platform already has the keys.
You don’t want to discover what the bug does after someone else starts moving files through the door.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
- ConnectWise Trust Center — September 3, 2026 ScreenConnect Remote Access Guest File Transfer Advisory
- ConnectWise security advisory and mitigation guidance
- BleepingComputer — ConnectWise warns of new ScreenConnect flaw without patch




