Wichtige Sicherheitsmitteilung: ScreenConnect – Schwachstelle und Update

Wichtige Sicherheitsmitteilung: ScreenConnect – Schwachstelle und Update

Vor Kurzem hat der Hersteller ConnectWise über ein empfohlenes ScreenConnect-Update informiert. 
Bitte entnehmen Sie der folgenden Hersteller-Nachricht vom 08.09.2026 weitere wichtige Handlungsempfehlungen und den Hotfix für Ihre ScreenConnect-Installation.

--

Dear ConnectWise Partner,

ConnectWise has issued a Security Bulletin on our Trust Center regarding a security update for ScreenConnect™ versions prior to 26.6.5.

This update addresses a condition in the ScreenConnect client that, under specific circumstances, may allow files to be transferred and executed through an active remote session without authorization or Host confirmation.

This issue requires unauthorized access to a valid ScreenConnect Support or Access session. Threat actors may use various tactics, techniques, and procedures to gain unauthorized access and subsequently misuse file-transfer functionality. ScreenConnect servers are not impacted.

The ScreenConnect 26.6.5 patch includes updates to strengthen client and session handling for file-transfer and file-execution actions.

We strongly recommend that all partners:
  • Upgrade to ScreenConnect™ version 26.6.5 as soon as possible.
    • Cloud-hosted ScreenConnect instances have been automatically upgraded to the latest version.
    • ScreenConnect On-prem partners will need to update manually to 26.6.5. Visit Download | ScreenConnect page to download and apply the update (access requires a valid on-premises license).
      • If your renewal is due in 2026, you are eligible to upgrade to 26.6.5 without renewing your license. Be sure to check your “Latest Eligible Version” on the Administration > Overview page to confirm your eligibility for 26.6.5.
      • Otherwise, if your license is out of maintenance, you must upgrade your license before installing the latest supported release of ScreenConnect.
      • If you are unable to apply the update immediately due to maintenance windows or change-freeze policies, you may temporarily reduce exposure by deselecting the TransferFiles (previously named TransferFilesInSession) permission for all user roles. This is a temporary mitigation only and should be used until the security update can be applied.
    1. Navigate to the Administration > Security > Roles section.
    2. Edit a role, review each session group that has permissions assigned to it, and deselect the TransferFiles permission if it is selected.
    3. Save your changes. Repeat for each role.
  • Review the Security Bulletin for additional details.

For help with upgrading visit ConnectWise Chat to open a case or email help@connectwise.com for additional support.

ConnectWise security bulletin
Please refer to the Security Bulletin posted to our Trust Center regarding this vulnerability for more detailed information.