Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Burnham and Trump expected to meet for first time next week as PM steps up presence on world stage | Andy Burnham

    September 16, 2026

    Amazon launches Alexa+ in India with Hindi support

    September 16, 2026

    Nums AI Releases Causilo: A Tabular Foundation Model That Tops TabArena Among Single Models

    September 16, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Burnham and Trump expected to meet for first time next week as PM steps up presence on world stage | Andy Burnham
    • Amazon launches Alexa+ in India with Hindi support
    • Nums AI Releases Causilo: A Tabular Foundation Model That Tops TabArena Among Single Models
    • Critical ScreenConnect flaw now actively exploited in attacks
    • UK Backs Money Laundering Crackdown With $676M and 500 New Officers
    • White-tailed eagle chicks fledge again amid reintroduction project
    • Colombia and Brazil deadliest countries for environmental defenders, report says
    • Is current Congress most productive in 80 years, as Mike Johnson claimed? We checked the numbers
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 16
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical ScreenConnect flaw now actively exploited in attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 16, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

    ConnectWise shared temporary mitigation measures for this missing-authorization flaw on September 7, advising security teams to disable TransferFiles permissions to block potential attacks.

    The vulnerability (now tracked as CVE-2026-84869 and patched in ScreenConnect 26.6.5 and later) affects ScreenConnect clients and can let threat actors with basic privileges transfer or execute files in low-complexity attacks that don’t require user interaction.

    CISA added the security flaw to its catalog of actively exploited flaws on Friday and ordered U.S. federal agencies to secure their systems against ongoing attacks within three days.

    “ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation,” CISA said. “These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.”

    Since 2024, CISA has flagged four ScreenConnect security issues as actively exploited, two of which have also been abused in ransomware attacks.

    Internet threat watchdog Shadowserver now tracks over 1,000 ScreenConnect instances still unpatched and exposed to attacks online, most of them from North America (758) and Europe (180).

    Vulnerable ScreenConnect instances
    Vulnerable ScreenConnect instances (Shadowserver)

    ​ScreenConnect vulnerabilities are often targeted in the wild by both financially-motivated and state-backed hacking groups.

    For instance, the North Korean-backed Kimsuky hacking group and several ransomware gangs exploited another ScreenConnect flaw (CVE-2024-1709) in 2024.

    Last year, ConnectWise also rotated digital code-signing certificates after disclosing that suspected state-sponsored hackers breached its systems through code injection attacks that exploited a ViewState flaw (CVE-2025-3935) and accessed the cloud-based instances of a limited number of customers.

    More recently, in March, ConnectWise addressed a cryptographic signature verification vulnerability (CVE-2026-3564) that could allow attackers to hijack unpatched ScreenConnect servers.

    ConnectWise provides services to more than 100,000 IT providers worldwide, with many managed service providers (MSPs) and IT teams using its ScreenConnect remote access platform for troubleshooting, patching, and system maintenance.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    actively attacks critical Exploited Flaw ScreenConnect
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

    Windows Server 2022 reaches end of mainstream support next month

    Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

    Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

    CISA: Critical VMware RCE flaw now exploited by ransomware gangs

    Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Burnham and Trump expected to meet for first time next week as PM steps up presence on world stage | Andy Burnham

    September 16, 2026

    Amazon launches Alexa+ in India with Hindi support

    September 16, 2026

    Nums AI Releases Causilo: A Tabular Foundation Model That Tops TabArena Among Single Models

    September 16, 2026

    Critical ScreenConnect flaw now actively exploited in attacks

    September 16, 2026
    Latest Posts

    Two new compounds could reveal hidden drivers of Alzheimer’s disease

    August 4, 2026

    Marmot Researchers Turn to OnlyFans for Funding—And There Are Meme Coins Too

    August 4, 2026

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Burnham and Trump expected to meet for first time next week as PM steps up presence on world stage | Andy Burnham

    September 16, 2026

    Amazon launches Alexa+ in India with Hindi support

    September 16, 2026

    Nums AI Releases Causilo: A Tabular Foundation Model That Tops TabArena Among Single Models

    September 16, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.