← Back to Feed

Critical ScreenConnect flaw now actively exploited in attacks

September 16, 2026 · BleepingComputer · Severity: CRITICAL

Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

Key Takeaways

  • A critical vulnerability in ScreenConnect remote desktop software is now being actively exploited in attacks, according to security vendor warnings.
  • The flaw allows unauthenticated remote code execution on ScreenConnect servers, potentially giving attackers full control over remote access infrastructure.
  • Organizations using ScreenConnect should apply the available patch immediately and audit for signs of unauthorized access.
☕ Buy a Coffee