Learn

The Remote-Access Tool Somebody Installed Years Ago Is Now the Problem

Every business has a few of these. A remote-support tool that a vendor installed to fix the accounting software in 2021. A little agent the previous IT company left behind when they moved on. A "let me take a look" client a scammer talked someone into installing during a fake Geek Squad call. They sit in the system tray, they never ask for anything, and nobody thinks about them again.

One of the most common of those tools is ConnectWise ScreenConnect, and on September 8th ConnectWise published a security bulletin about it that deserves a business owner's attention, not just an IT person's.

What the flaw is

ConnectWise rated it 9.9 out of 10. The short version: an attacker who gets into an active remote session can transfer files to the computer on the other end and run them, without the approval step that is supposed to stop exactly that. Every version of the ScreenConnect client before 26.6.5 is affected.

The part that changes how you have to respond is this sentence from the bulletin: the servers are not impacted. The vulnerability lives in the client, the small program on each individual computer. So if your IT provider hosts ScreenConnect in ConnectWise's cloud, their server was updated automatically. Your computers were not. ConnectWise's own guidance is that host clients have to be reinstalled and access agents updated after the server is patched. A cloud customer who reads "cloud instances are upgraded automatically" and stops there still has an unpatched client on every desk.

It is already being used

Security firm Huntress wrote up a campaign it tracked in late August, before the patch existed. Attackers got a rogue ScreenConnect client onto a first machine through ordinary tricks: a tech-support scam over Microsoft Quick Assist, a phishing email carrying the installer, a poisoned search result for a refund form. Once installed, the client ran a chain of four small scripts and planted a startup entry so it would survive a reboot.

Then it did something remote-access tools are not supposed to do. It watched for the next technician connection and pushed the same script chain down to that computer through ScreenConnect's own file-transfer feature. That is how a compromise on one machine turned up on unrelated machines at unrelated companies. Huntress's advice for an affected computer is blunt: rebuild it from known-good media. There is no cleaning it in place.

What we found on our own fleet

Because the fix is per computer, the only way to know your exposure is to inventory every computer. So we did that for every machine we manage before we contacted anyone.

Two things stood out.

First, the tool is far more common than anyone had said. We found ScreenConnect at four organizations, on well over a hundred machines between them. None of those organizations had told us ScreenConnect was in use, because in most cases the people who installed it were long gone. Roughly one install in five was below the patched version, and one of them was a domain controller running a client from 2023.

Second, the installs traced back to five separate ScreenConnect instances, meaning five separate parties who at some point had remote control of those computers. For two of the five, nobody at the organization could say who that party was. One laptop carried two different ScreenConnect clients at once, which is exactly the shape the August campaign produces.

That last point is the real lesson. The vulnerability got the headline, but the underlying problem is older and simpler: a remote-access agent is a standing door into a computer, and most businesses have no list of the doors.

What to do this week

You do not need to understand the flaw to act on it. You need to know what is installed.

  1. Get a list of every remote-access tool on every computer. Not just ScreenConnect. On the machines we checked we also found Splashtop, GoToAssist, LogMeIn, Zoho Assist, RemotePC, TeamViewer, AnyDesk, and a few rarer ones. Your IT provider can pull this from their management software in an afternoon. If they cannot, that is worth knowing too.

  2. For every tool, name the owner. Which vendor, which former provider, which employee. If nobody can name the owner, the agent is removed. An unowned remote-control tool has no legitimate reason to exist.

  3. For ScreenConnect specifically, get the client version on each machine. Anything below 26.6.5 is either updated by whoever owns the instance, or uninstalled. A domain controller or a server goes first.

  4. Ask the owner of any instance that stays to turn off file transfer on every role until they confirm the update. ConnectWise's interim mitigation is exactly that: in the administration console, under roles, deselect the TransferFiles permission. It closes the hole the campaign walks through.

  5. If a machine shows the signs, rebuild it. Two ScreenConnect clients on one computer, a startup entry called WindowsServiceHost, or script files named 1.vbs through 4.vbs in a temp folder. Do not try to clean it. Reimage it.

The part that outlasts this bulletin

There will be another remote-access flaw. Every one of these tools has had one, and the attackers who ran the August campaign did not need a flaw at all to get their first foothold. They needed one person to approve a Quick Assist session.

So the durable fix is not a patch. It is a rule: one remote-access tool, owned by one party you can name, on a list you can produce on request, with everything else removed. Get to that state once and the next bulletin becomes a version check instead of an investigation.

Do you know how many remote-control agents are on your computers right now, and who holds the other end of each one?

Sources: ConnectWise security bulletin of September 8, 2026 (CVE-2026-84869, fixed in ScreenConnect 26.6.5); Huntress, "Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity," September 9, 2026; BleepingComputer, "ConnectWise warns of new ScreenConnect flaw without patch," September 7, 2026. Fleet figures are aggregated from our own managed environment and identify no organization.

Get the next one by email

A new post most Tuesdays, written for the person who runs the business. One email per post, unsubscribe any time.