ConnectWise has warned customers about a new vulnerability in ScreenConnect Remote Access and, according to BleepingComputer, has not yet shipped a permanent patch. The company has instead published temporary mitigation steps while it works on a fix it plans to release later this week. ScreenConnect is a remote-access platform used by managed service providers, internal IT teams, and support organizations to troubleshoot, patch, and maintain systems. That makes any weakness in the product operationally sensitive: the tool is designed to reach into customer environments, often with elevated trust and broad administrative reach. BleepingComputer reports that the flaw affects both cloud-hosted and on-premises ScreenConnect deployments. The issue has not yet been assigned a CVE identifier, which makes tracking harder for security teams that rely on vulnerability-management systems, scanners, and ticketing workflows built around CVE records. The company described the problem in a Thursday advisory as an issue involving file transfer behavior in ScreenConnect Remote Access Support and Access sessions, according to BleepingComputer. The provided material does not include the full technical mechanics of the bug or the specific mitigation steps, so defenders should treat ConnectWise’s advisory as the source of record for configuration guidance until the patch lands. The exposed-attack-surface question is material. BleepingComputer cites Shadowserver data showing nearly 6,000 ScreenConnect instances visible online, while also noting that it is not clear how many of those are honeypots or have already been secured. That caveat matters: exposure counts can overstate or understate real risk depending on asset ownership, versioning, and whether mitigations have already been applied. The warning lands against a recent history of ScreenConnect exploitation. BleepingComputer notes that in 2024, ransomware gangs and the Kimsuky North Korean advanced persistent threat group exploited another ScreenConnect flaw, CVE-2024-1709, to deploy malware on vulnerable systems. The outlet also reports that ConnectWise disclosed last year that suspected state-sponsored hackers breached its systems through a high-severity ViewState code-injection vulnerability, CVE-2025-3935, gaining access to the cloud-based instances of a limited number of customers. BleepingComputer adds that ConnectWise addressed another ScreenConnect vulnerability in March, tracked as CVE-2026-3564, involving cryptographic signature verification and possible hijacking of unpatched instances. Since February 2024, the U.S. Cybersecurity and Infrastructure Security Agency has added three ScreenConnect vulnerabilities to its catalog of actively exploited flaws, two of which were also used in ransomware attacks, according to the report. For now, the story is less about a completed patch cycle than about exposure management. Organizations using ScreenConnect need to identify whether they run affected cloud or on-premises deployments, apply ConnectWise’s temporary mitigations, and watch for the promised update later this week. Who benefits: Security teams benefit from early notice and temporary mitigations before a patch is available. Attackers also benefit from the window between advisory and fix if exposed instances remain reachable and unmitigated. Who's exposed: Organizations running ScreenConnect Remote Access in cloud or on-premises deployments are the directly exposed group, according to BleepingComputer. Managed service providers face added risk because compromise of a support platform can affect downstream customers.