ConnectWise ScreenConnect Vulnerability Under Active Exploitation, CISA Confirms

A critical-severity flaw in ConnectWise ScreenConnect is being actively exploited in the wild, with CISA issuing a warning to organisations running the remote access platform.

AI-generated illustration depicting policy for the story: ConnectWise ScreenConnect Vulnerability Under Active Exploitation, CISA Confirms

Summary

  • A critical vulnerability in ConnectWise ScreenConnect is now being actively exploited by attackers.
  • CISA has confirmed the exploitation activity, raising the urgency for organisations still running unpatched versions.
  • ScreenConnect is widely deployed in enterprise and managed service provider environments, broadening the potential attack surface.
  • Organisations using ScreenConnect should treat patching as an immediate priority, not a scheduled maintenance item.
  • The sources do not detail specific threat actors or confirmed victim organisations at this stage.

What We Know

The U.S. Cybersecurity and Infrastructure Security Agency has confirmed that a critical-severity vulnerability in ConnectWise ScreenConnect is now being actively exploited in attacks. The disclosure moves this flaw from a theoretical risk to a confirmed, live threat — a meaningful shift that changes how security teams should be prioritising their response.

The Platform in Question

ScreenConnect is a remote desktop and access management tool from ConnectWise, commonly used by IT teams and managed service providers to administer endpoints across client environments. Its widespread deployment — particularly in MSP ecosystems — means a single exploitable instance can serve as an entry point into multiple downstream organisations. That reach is precisely what makes vulnerabilities in remote access tooling disproportionately dangerous.

What the Sources Don’t Tell Us

The available source material confirms active exploitation and CISA’s involvement, but does not identify the specific threat actors behind the attacks, the number or nature of confirmed victims, or the precise technical mechanism being abused. The sources also do not specify which versions are affected beyond characterising the flaw as critical-severity. Security teams should monitor ConnectWise’s official advisories and CISA’s Known Exploited Vulnerabilities catalogue for that granularity.

Why Remote Access Tools Attract Attention

Remote access platforms occupy a privileged position in most enterprise architectures. They are trusted, they operate with elevated permissions, and they are typically reachable from the internet by design. That combination makes them an attractive initial access vector for ransomware operators, espionage groups, and opportunistic cybercriminals alike. When a critical flaw in such a tool moves to active exploitation, the window between vulnerability disclosure and compromise shortens considerably — sometimes to hours.

The Managed Service Provider Dimension

For organisations that rely on MSPs running ScreenConnect, the risk is not solely your own patch cadence — it is also your provider’s. A compromised MSP instance can be leveraged to pivot into client environments without those clients having any direct exposure themselves. This is a supply chain risk in practical terms, and it warrants direct conversations with service providers about their patch status and any indicators of compromise they may be investigating.

CISA’s Role and What It Signals

When CISA confirms active exploitation of a vulnerability, it is drawing on threat intelligence that goes beyond public reporting. The agency’s Known Exploited Vulnerabilities catalogue exists specifically to drive prioritisation in both government and private sector environments. An entry there — or a public confirmation of exploitation — is a signal that the flaw has crossed from proof-of-concept territory into operational use by real adversaries.

Why it matters

ScreenConnect’s prevalence in MSP environments creates a multiplier effect: a single compromised instance can expose an entire client portfolio. For CISOs, this is both a direct patching obligation and a third-party risk question. The confirmation of active exploitation by CISA removes any ambiguity about urgency — this is not a vulnerability to queue for the next patch cycle. Security leaders should be verifying patch status now, reviewing access logs for anomalous ScreenConnect activity, and having direct conversations with any MSPs operating the platform on their behalf.

What to do now

  • Identify all ScreenConnect instances in your environment and verify whether they are running a patched version, referencing ConnectWise’s official security advisory for affected version details.
  • Check CISA’s Known Exploited Vulnerabilities catalogue for specific remediation guidance and deadlines applicable to federal and critical infrastructure operators.
  • Review ScreenConnect access logs for unusual authentication patterns, unexpected session initiations, or access from unfamiliar IP addresses.
  • Contact any managed service providers operating ScreenConnect on your behalf to confirm their patch status and request confirmation they are investigating for indicators of compromise.
  • If patching cannot be completed immediately, assess whether internet-exposed ScreenConnect instances can be temporarily restricted or taken offline to reduce exposure.

Sources