INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Critical ScreenConnect flaw now actively exploited in attacks
| 2026-09-16 11:14 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The recent ScreenConnect security issues have been actively exploited in various attacks, including ransomware and ViewState flaw-based assaults. A critical vulnerability (CVE-2026-84869) has been identified on the platform, allowing threat actors to transfer or execute files without user interaction. This flaw affects over 1,000 unpatched instances still exposed online, with most being targeted from North America and Europe. The vulnerabilities have been tracked by Internet threat watchdog Shadowserver since September 2024, indicating a long-standing issue that has not received timely attention.
Technical Mitigations AI-generated
* Disable TransferFiles permissions to block potential attacks on ScreenConnect clients.
* Edit user roles and check session groups with permissions assigned to them, specifically deselecting the TransferFiles permission (or TransferFilesInSession for legacy) for each session group.
* Log in to the ScreenConnect Administration page and go to Administration > Security > Roles to update role settings.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
KimsukyKimsuky
CVE-2025-3935CVE-2025-3935
CVE-2026-84869CVE-2026-84869
CVE-2026-3564CVE-2026-3564
CVE-2024-1709CVE-2024-1709
Target & Sectors
EUROPE
EUROPE
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
technologytechnology
Incident Timeline
February 2024
Ransomware groups have been using the ScreenConnect vulnerabilities to target systems.
Click on any entity below to view its context and source!
tactic
Ransomware
Since February 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added
three ScreenConnect vulnerabilities
to its catalog of actively exploited flaws, two of which were also abused in ransomware attacks.
2025/09/07
Threat actors used ViewState to target CloudConnectWise instances.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-3935
Last year, ConnectWise disclosed that suspected state-sponsored hackers breached its systems via a high-severity ViewState code injection bug (
CVE-2025-3935
) and gained access to the cloud-based instances of a limited number of customers.
attribution
ViewState
Last year, ConnectWise disclosed that suspected state-sponsored hackers breached its systems via a high-severity ViewState code injection bug (
CVE-2025-3935
) and gained access to the cloud-based instances of a limited number of customers.
2025/09/16
Threat actors used a ViewState flaw to exploit CVE-2025-3935 in attacks targeting customers of ScreenConnect.
Click on any entity below to view its context and source!
attribution
CVE-2025-3935
Last year, ConnectWise also
rotated digital
code-signing certificates
after disclosing that
suspected state-sponsored hackers breached its systems
through code injection attacks that exploited
a ViewState flaw (CVE-2025-3935) and accessed the cloud-based instances of
a limited number of customers.
attribution
ViewState
Last year, ConnectWise also
rotated digital
code-signing certificates
after disclosing that
suspected state-sponsored hackers breached its systems
through code injection attacks that exploited
a ViewState flaw (CVE-2025-3935) and accessed the cloud-based instances of
a limited number of customers.
September 7
Threat actors exploited a critical ScreenConnect flaw by using it to target ConnectWise systems.
Click on any entity below to view its context and source!
organisation
ConnectWise
ConnectWise
shared
temporary mitigation measures
for this missing-authorization flaw on September 7, advising security teams to disable TransferFiles permissions to block potential attacks.
organisation
TransferFiles
ConnectWise
shared
temporary mitigation measures
for this missing-authorization flaw on September 7, advising security teams to disable TransferFiles permissions to block potential attacks.
2026/09/16
North Korean-backed Kimsuky hacking groups exploited a critical ScreenConnect flaw (CVE-2024-1709) in 2024 to drop malware on vulnerable systems.
Click on any entity below to view its context and source!
threat_actor
Kimsuky
For instance,
the
North
Korean-backed Kimsuky hacking group
and
several ransomware gangs
exploited another ScreenConnect flaw (CVE-2024-1709) in 2024.
For instance, in 2024,
ransomware gangs
and the
Kimsuky North Korean APT hacking group
exploited another ScreenConnect flaw (tracked as
CVE-2024-1709
) to drop malware on vulnerable systems.
organisation
APT
For instance, in 2024,
ransomware gangs
and the
Kimsuky North Korean APT hacking group
exploited another ScreenConnect flaw (tracked as
CVE-2024-1709
) to drop malware on vulnerable systems.
organisation
ScreenConnect
The vulnerability (now tracked as
CVE-2026-84869
and patched in ScreenConnect 26.6.5 and later) affects ScreenConnect clients and can let threat actors with basic privileges transfer or execute files in low-complexity attacks that don't require user interaction.
ConnectWise warns of new ScreenConnect flaw without patch.
organisation
ConnectWise
ConnectWise warns of new ScreenConnect flaw without patch.
financial
180 Europe
Internet threat watchdog Shadowserver now tracks
over 1,000 ScreenConnect instances
still unpatched and exposed to attacks online, most of them from North America (758) and Europe (180).
organisation
CVE-2026-3564
More recently, in March, ConnectWise
addressed a cryptographic signature verification vulnerability
(CVE-2026-3564) that could allow attackers to hijack unpatched ScreenConnect servers.
organisation
Critical ScreenConnect
Critical ScreenConnect flaw now actively exploited in attacks.
organisation
TransferFiles
In the Scoped Permissions window, deselect the TransferFiles permission (or TransferFilesInSession for legacy) for each session group.
organisation
Scoped Permissions
In the Scoped Permissions window, deselect the TransferFiles permission (or TransferFilesInSession for legacy) for each session group.
organisation
Vulnerable ScreenConnect
Vulnerable ScreenConnect instances (Shadowserver)
ScreenConnect vulnerabilities are often targeted in the wild by both financially-motivated and state-backed hacking groups.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
ScreenConnect Remote Access
ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week.
organisation
ScreenConnect Administration
This requires IT administrators to go through the following steps:
Log in to the ScreenConnect Administration page.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Tactical Metrics
Metrics
financial
180
Europe
Click for context!
Internet threat watchdog Shadowserver now tracks
over 1,000 ScreenConnect instances
still unpatched and exposed to attacks online, most of them from North America (758) and Europe (180).
Intelligence Sources
BleepingComputer
2026-09-16
Critical ScreenConnect flaw now actively exploited in attacks
BleepingComputer
BleepingComputer
2026-09-07
ConnectWise warns of new ScreenConnect flaw without patch
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-17T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
ScreenConnect
entity
5x
timeline
Temporal Reference
2024
date
4x
vulnerability
Exploited CVE
CVE-2024-1709
cve
4x
attribution
Attributing Entity
ViewState
authority
2x
target region
Target Region
EUROPE
region
2x
general metric
Screenconnect Instances
1,000
screenconnect instances
Contextual Telemetry
Context Block
8 METRICS
tactic
Cyber Operation Type
Ransomware
tactic
threat actor
APT Group
Kimsuky
actor
general metric
North America
758
north america
financial
Europe
180
europe
general metric
It Providers
100,000
it providers
source region
Origin Region
DPRK
region
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.