ScreenConnect Rogue Clients Turn Support Into Spread

Huntress and ConnectWise said rogue ScreenConnect clients are using a file-transfer flaw in ScreenConnect Remote Access, Support, and Access sessions to spread malware to every machine that later connects. ConnectWise said the issue affects both Cloud and on-prem deployments and that a CVE identifier and fix will be issued within the week. The attack starts when an attacker plants a fake ScreenConnect client on one host, then uses later support sessions to push scripts and other payloads onto new connecting systems. That makes the remote-support link itself the delivery path, so the original foothold can keep infecting later endpoints instead of staying contained to one victim machine. For organizations that run ScreenConnect as a live support channel, the exposure follows the workflow, not just the first compromised endpoint. If file transfer and related session permissions stay open, a rogue instance can keep widening the incident until it is removed from the environment.

Part of the PlainSec briefing for 2026-09-07

Editions

Sources