ScreenConnect attacks turn trusted remote access into an entry point
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, September 18th, 2026.
Attackers are now exploiting ScreenConnect to transfer or execute files through active remote sessions without proper authorization or confirmation from the host user. The issue affects ScreenConnect clients and is fixed in version 26.6.5 and later. CISA added it to the Known Exploited Vulnerabilities catalog and required rapid remediation by federal agencies. At the time of reporting, more than one thousand unpatched ScreenConnect instances remained exposed online, including 758 in North America and 180 in Europe.
The concern is bigger than one vulnerable application. A compromised remote-support path can give attackers a trusted route into managed endpoints, and service providers may face amplified exposure because one platform can connect to many customer systems. Leaders should treat remote-management infrastructure as a high-value control plane, not an ordinary support tool. Defenders should patch, restrict external access, and review remote sessions, file transfers, child processes, and administrative accounts. Upgrade every ScreenConnect deployment to 26.6.5 or later, then perform forensic triage for signs of unauthorized activity rather than assuming the patch alone resolves the risk.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.