CuraSec

Act active

Critical ConnectWise ScreenConnect flaw actively exploited in the wild

2026-09-16 15:25 UTC · BleepingComputer · read the source ↗ #screenconnect#remote-access#active-exploitation
  • Engineer — Act: A critical ScreenConnect vulnerability is under active exploitation with CISA issuing a warning — patch ConnectWise ScreenConnect to the latest patched version immediately, or isolate/disable instances until patching is complete.
  • SOC/IR — Act: Active exploitation of a remote access tool is a priority assume-breach scenario; hunt for anomalous ScreenConnect sessions, unexpected remote access activity, and lateral movement originating from ScreenConnect processes since the disclosure date.
  • Leader — Act: Confirm whether ScreenConnect is in use across your environment (including MSP vendors who may use it to manage your systems) and verify emergency patching is underway; active exploitation of remote access tools frequently precedes ransomware deployment.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.