Start your day with intelligence. Get The OODA Daily Pulse.

Home > Briefs > Cyber > ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

ConnectWise patches critical ScreenConnect flaw amid active exploitation.

ConnectWise issued an urgent fix for a ScreenConnect vulnerability that allowed attackers to transfer and execute files during remote sessions without authorization. Huntress reported that hackers had already used modified clients to push VBScript payloads that spread to other ScreenConnect installations and established persistence. The attacks relied on social engineering to get victims to run rogue clients, which then searched for active sessions to deliver the scripts. ConnectWise released version 26.6.5 to address the flaw and advised disabling file‑transfer permissions until systems are updated, while CISA added the bug to its KEV list and ordered rapid patching.

Read more:

https://www.securityweek.com/connectwise-patches-screenconnect-vulnerability-exploited-in-worm-like-attacks/