Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Mathspace Data Breach Exposes 1 Million Users’ Personal Info
September 7, 2026
Hackers Hide Credential-Stealing Phishing in Google Services
September 7, 2026
OpenAI Pledges $1 Billion for Critical Infrastructure AI Cybersecurity Tools
September 7, 2026
Home/Vulnerabilities/ConnectWise Patches Critical ScreenConnect Vulnerability CVE-2024-46805
Vulnerabilities

ConnectWise Patches Critical ScreenConnect Vulnerability CVE-2024-46805

Key Takeaways ConnectWise has identified a critical security vulnerability, CVE-2024-46805, impacting file transfer functionality in its ScreenConnect Remote Access Support and Access sessions. Both...

Marcus Rodriguez
Marcus Rodriguez
September 7, 2026 3 Min Read
3 0

Key Takeaways

  • ConnectWise has identified a critical security vulnerability, CVE-2024-46805, impacting file transfer functionality in its ScreenConnect Remote Access Support and Access sessions.
  • Both cloud-hosted and on-premises ScreenConnect deployments are affected.
  • The vulnerability carries a CVSS score of 10.0, indicating maximum severity.
  • ConnectWise has released an emergency patch for cloud environments and urges all self-hosted users to update immediately to version 23.9.10 or later.
  • While the specific attack vector remains undisclosed, the potential for unauthorized file transfers poses a significant risk to managed endpoints and internal systems.

ConnectWise Issues Urgent Patch for Critical ScreenConnect Vulnerability CVE-2024-46805

ConnectWise has released an urgent patch addressing a critical security vulnerability, tracked as CVE-2024-46805, within its ScreenConnect Remote Access Support and Access sessions. The flaw, which received the highest possible CVSS score of 10.0, affects the platform’s file transfer functionality and impacts both cloud-hosted and on-premises deployments.

Table Of Content

  • Key Takeaways
  • ConnectWise Issues Urgent Patch for Critical ScreenConnect Vulnerability CVE-2024-46805
  • Vulnerability Details and Impact
  • Immediate Mitigation Steps and Official Patch
  • What You Should Do

The vendor’s advisory, initially published on September 3, 2026, alerted customers to a newly discovered security issue related to file transfer behavior. While ConnectWise initially withheld the CVE identifier and technical specifics, an emergency update has now been rolled out for cloud environments, and self-hosted users are strongly advised to update to version 23.9.10 or later.

Vulnerability Details and Impact

The vulnerability specifically targets CW Remote Access, previously known as ScreenConnect, and is confined to Support and Access sessions. ConnectWise has not yet publicly disclosed the precise technical details regarding how malicious actors could exploit this file transfer behavior, the potential attack scenarios, or whether active exploitation has been observed in the wild. However, the critical CVSS score underscores the severe risk posed by this flaw.

Remote access platforms are highly attractive targets for cybercriminals due to their direct access to managed endpoints, internal networks, and sensitive customer data. A vulnerability allowing unauthorized file transfers could enable attackers to exfiltrate data, inject malware, or escalate privileges within compromised environments.

Immediate Mitigation Steps and Official Patch

The advisory applies universally to all ScreenConnect Remote Access instances, whether deployed through ConnectWise’s cloud infrastructure or self-hosted. ConnectWise said it has now released an official patch for the underlying file-transfer behavior. Cloud environments have been updated, and self-hosted users must upgrade to version 23.9.10 or a subsequent release.

Before the official patch was available, ConnectWise had recommended interim mitigation steps, specifically restricting technician file-transfer privileges. This temporary measure aimed to reduce the attack surface by disabling the ability for technicians to transfer files through affected remote-access sessions.

Organizations that have not yet updated their self-hosted ScreenConnect instances must do so immediately. The process of applying the patch is critical for securing their environments against potential exploitation.

What You Should Do

  • Upgrade Immediately: For self-hosted ScreenConnect deployments, update to version 23.9.10 or later without delay. Cloud environments should already be patched.
  • Review User Roles and Permissions: Conduct a thorough review of all user roles, session groups, and file-transfer permissions within your ScreenConnect environment. Ensure that the TransferFiles or TransferFilesInSession permission is disabled for any roles that do not absolutely require it.
  • Monitor ConnectWise Advisories: Continuously monitor the ConnectWise advisory page for any further updates, additional guidance, or details on affected versions.
  • Audit Administrative Accounts: Verify that only authorized personnel have privileged roles within ScreenConnect and regularly audit these accounts.
  • Monitor Activity Logs: Actively monitor remote-support activity for any unusual file-transfer attempts, unexpected changes to role permissions, or suspicious access patterns.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

New Linux Botnet Masquerades as Kernel Process to Launch DDoS Attacks

Next Post

Natural Resources Wales Exposes Sensitive Employee Data

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
ConnectWise Patches Critical ScreenConnect Vulnerability CVE-2024-46805
September 7, 2026
New Linux Botnet Masquerades as Kernel Process to Launch DDoS Attacks
September 7, 2026
LG Smart TVs Vulnerable to Network Scanning and Audio Logging in Standby
September 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us