CISA Warns of Active ScreenConnect Exploitation: What to Do Now

What happened
CISA has confirmed that attackers are actively exploiting a critical-severity vulnerability in ConnectWise ScreenConnect, the widely used remote-support and remote-access platform. The details were reported by BleepingComputer, which notes that the federal cyber agency is warning organizations about in-the-wild exploitation rather than theoretical risk.
We are not going to guess at the specific CVE number, affected build ranges, or CISA remediation dates here, because those details move fast and getting them wrong is worse than not stating them. What every business should do instead is verify the exact patched version and any federal deadline directly against ConnectWise's security advisory page and CISA's Known Exploited Vulnerabilities catalog, then confirm in writing that your own environment matches. If you use ScreenConnect on-premises anywhere in your business, treat this as an emergency change, not a routine patch cycle item.

Why this matters for Pittsburgh SMBs
Remote-access tooling is the softest, highest-value target in the entire small-business technology stack. A ScreenConnect server does not just run software; it holds a trusted, silent path onto every endpoint that has an agent installed. When that platform is compromised, an attacker does not need to phish anyone, crack a password, or defeat multifactor authentication. They arrive already looking like your IT department, with the ability to push files, run scripts, and open sessions at 2 a.m. That is exactly how several of the most damaging ransomware campaigns against mid-market companies have started.
For a 40-person CPA firm in the South Hills, that means an intruder inside the machines holding client tax files during a filing season crunch. For a Pittsburgh law firm, it means privileged work product and matter files exposed, which is a bar-notification problem as much as a security one. For a specialty medical practice, a compromised remote-access session touching systems that handle PHI is a HIPAA Security Rule incident that requires investigation and, potentially, breach notification. Manufacturers along the river corridors face the operational version of the same problem: an attacker who can script commands across endpoints can reach shop-floor scheduling, ERP, and quality systems, and downtime there is measured in missed customer commitments.
Defense contractors carry the sharpest exposure. If you handle CUI under DFARS 7012 and are working toward or maintaining CMMC Level 2, remote-access controls, vulnerability remediation timelines, and incident reporting are all assessed practices. An unpatched, internet-facing remote-access server that CISA has flagged as actively exploited is not just a technical gap; it is an assessment finding waiting to be written up, and a 72-hour DoD incident report waiting to be filed.
There is also a supply-chain dimension worth saying out loud. This is MSP tooling. If you outsource IT, you should be asking your provider what they run, whether it is patched, and how they would tell you if it were not. A vendor who cannot answer that quickly is telling you something.
What to do about it this week
- Inventory every instance of ScreenConnect in your environment. Include self-hosted servers, cloud instances, agents left behind on retired machines, and copies installed by former vendors or software resellers. Shadow remote-access tools are extremely common in companies that have changed IT providers. Search endpoints for the agent, not just your asset list.
- Get written confirmation from your IT provider today. Ask three specific questions: which version are we on, is it the version ConnectWise identifies as remediated, and when was it applied? Ask the same about the provider's own management platform, not only yours. Save the answer, because auditors and cyber insurance carriers will ask later.
- Patch or take it offline. If you self-host and cannot confirm you are on a remediated build, remove public internet exposure while you remediate. A brief interruption to remote support beats an incident response engagement.
- Hunt for signs you were already hit. Review remote-session logs for unfamiliar technician accounts, sessions outside business hours, new admin users, unexpected file transfers, and scheduled tasks or scripts you did not authorize. Confirm your EDR or MDR platform has telemetry retained long enough to look backward, not just forward.
- Tighten access around the tool itself. Enforce MFA on every remote-access console account, restrict administrative access to known IP ranges or a VPN, remove dormant technician accounts, and disable unattended access on endpoints that do not need it.
- Verify your backups are actually recoverable and out of reach. Confirm immutable or offline copies, then test a restore of one critical system. Backups that live on the same network an intruder controls are not backups.
- Refresh your incident response and notification math. Write down who calls counsel, your carrier, and, where applicable, your contracting officer. If you are subject to HIPAA, SOC 2, or FTC Safeguards obligations, know your clocks before you need them, and note that FTC Safeguards notification runs on a 30-day trigger from discovery of a qualifying event, meaning an incident discovered today puts you on the hook by mid-October.
How we help
Our managed IT and cybersecurity teams handle exactly this kind of fire drill for Pittsburgh-area businesses: emergency patch validation, remote-access hardening, log review for signs of prior access, and clear documentation your auditor or insurer will accept. If you would rather not find out during your next assessment whether your remote-access posture holds up, our vCIO team can build that into a technology roadmap instead of a scramble.
Call us at 724.888.7007 or reach out through the contact form, and we will help you confirm where you stand before someone else does.
Related reading

CISA Flags Actively Exploited ScreenConnect and RouterOS Flaws
CISA added five actively exploited Artifactory, ScreenConnect and RouterOS flaws to its KEV catalog. Here is what Pittsburgh SMBs should verify and patch this week.

CISA Flags Exploited Cisco, Citrix and Fortinet Flaws
CISA added actively exploited Cisco, Citrix and Fortinet flaws to its KEV catalog with a Sept. 12 federal patch deadline. What Pittsburgh SMBs should do now.

Record Microsoft Patch Tuesday: 974 Flaws, Two Zero-Days
Microsoft patched a record 974 vulnerabilities including two exploited Windows zero-days. What Pittsburgh SMBs should verify and patch this week.