Active ScreenConnect attacks threaten trusted remote access
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Thursday, September 17th, 2026.
Attackers are actively exploiting a ScreenConnect weakness that can turn a trusted remote session into a delivery path for unauthorized files. CISA added the issue to its Known Exploited Vulnerabilities catalog and required urgent remediation by federal agencies. The weakness affects ScreenConnect clients and can allow file transfer or execution through an active remote session without host confirmation. ScreenConnect 26.6.5 and later contain the fix, but more than one thousand exposed instances were still reported as unpatched.
Remote support platforms create special risk because they can provide access to many managed endpoints, particularly in environments supported by service providers. Installing the update is essential, but patching alone won’t show whether an attacker already abused a legitimate-looking session.
Leaders should confirm that internal teams and outside providers have clear responsibility for both remediation and investigation. Defenders should review remote sessions, file transfers, child processes and exposed servers for suspicious activity. Trusted administration tools remain attractive because malicious actions can blend into ordinary support work. Upgrade every ScreenConnect deployment and conduct forensic triage of exposed servers, active sessions and managed endpoints.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.