INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Critical ScreenConnect flaw now actively exploited in attacks

| 2026-09-16 11:14 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The recent ScreenConnect security issues have been actively exploited in various attacks, including ransomware and ViewState flaw-based assaults. A critical vulnerability (CVE-2026-84869) has been identified on the platform, allowing threat actors to transfer or execute files without user interaction. This flaw affects over 1,000 unpatched instances still exposed online, with most being targeted from North America and Europe. The vulnerabilities have been tracked by Internet threat watchdog Shadowserver since September 2024, indicating a long-standing issue that has not received timely attention.
Technical Mitigations AI-generated
* Disable TransferFiles permissions to block potential attacks on ScreenConnect clients. * Edit user roles and check session groups with permissions assigned to them, specifically deselecting the TransferFiles permission (or TransferFilesInSession for legacy) for each session group. * Log in to the ScreenConnect Administration page and go to Administration > Security > Roles to update role settings.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
KimsukyKimsuky CVE-2025-3935CVE-2025-3935 CVE-2026-84869CVE-2026-84869 CVE-2026-3564CVE-2026-3564 CVE-2024-1709CVE-2024-1709
Target & Sectors
EUROPE EUROPE NORTH_AMERICA NORTH_AMERICA governmentgovernment technologytechnology
Incident Timeline
‎February 2024
Ransomware groups have been using the ScreenConnect vulnerabilities to target systems.
tactic Ransomware
‎2025/09/07
Threat actors used ViewState to target CloudConnectWise instances.
vulnerability CVE-2025-3935
attribution ViewState
‎2025/09/16
Threat actors used a ViewState flaw to exploit CVE-2025-3935 in attacks targeting customers of ScreenConnect.
attribution CVE-2025-3935
attribution ViewState
‎September 7
Threat actors exploited a critical ScreenConnect flaw by using it to target ConnectWise systems.
organisation ConnectWise
organisation TransferFiles
‎2026/09/16
North Korean-backed Kimsuky hacking groups exploited a critical ScreenConnect flaw (CVE-2024-1709) in 2024 to drop malware on vulnerable systems.
threat_actor Kimsuky
organisation APT
organisation ScreenConnect
organisation ConnectWise
financial 180 Europe
organisation CVE-2026-3564
organisation Critical ScreenConnect
organisation TransferFiles
organisation Scoped Permissions
organisation Vulnerable ScreenConnect
organisation NFL
organisation CHANEL
organisation ScreenConnect Remote Access
organisation ScreenConnect Administration
organisation The Blue Report 2026
Tactical Metrics
Metrics
financial
180
Europe
Intelligence Sources
BleepingComputer 2026-09-16
BleepingComputer 2026-09-07