← Back to blog Cybersecurity

Critical ScreenConnect flaw under active exploitation: what to do if your Mexico operation or its IT provider uses this remote access tool

4 min read

On September 16, 2026, BleepingComputer reported that a critical flaw in ConnectWise ScreenConnect is now being actively exploited in attacks. Not a theoretical advisory: someone is walking through that door today.

If you run a plant, warehouse or office in Mexico from abroad, this one lands close. ScreenConnect is the tool your local IT provider, or your own help desk back home, most likely uses to reach the PCs in Monterrey or Querétaro without flying anyone in.

What ScreenConnect is and why it matters even if you never installed it

The service entrance to your network A remote access tool is a master key. It exists to fix things, which is exactly why it also opens things.

A remote access tool leaves a small program on every PC, the agent, that waits for an authorized technician to connect. That is why the accountant in your Mexico office does nothing when someone fixes their Excel: a technician connects, sees the screen and sorts it out.

A critical flaw in that tool means whoever exploits it may end up holding the same key as your technician, on every machine at once. In our experience, an attacker who arrives through the provider’s tool does not look like an intruder. They look like support.

There are two ways to run ScreenConnect. On-premise means the server sits in your company or your provider’s, and a person has to patch it by hand. Cloud means ConnectWise hosts and updates it. Which one you have changes everything this week.

If the instance is yours: patch today

Server first, then the sessions The patch closes the flaw. The session review tells you whether someone already used it before you did.

If your headquarters IT team runs its own ScreenConnect server to reach Mexico, the order is:

  1. Update to the fixed version ConnectWise lists. Today, not Friday.
  2. Review the session history for the last few days. Look for connections at odd hours, from countries where you have nobody, or to PCs nobody reported as broken.
  3. Check the extensions installed on the server. One nobody remembers adding is a red flag.
  4. Rotate admin passwords and turn on a second factor if it was off.
  5. If something looks wrong, do not delete it. Isolate the machine and get help. Evidence matters.

How to find the agent on the PCs in Mexico

Many foreign managers do not know which tool the local provider uses. Here is how to check without calling anyone. A screenshot from the site is enough.

Where to lookWhat to look for
Control Panel, Programs“ScreenConnect Client” followed by a long code
Windows ServicesA service starting with ScreenConnect Client
Tray next to the clockA small ConnectWise or ScreenConnect icon
Mac, Applications or Activity Monitor“ScreenConnect Client” or “connectwisecontrol” process

Write down the code. It identifies which server that agent reports to, so your provider knows exactly which instance to check.

If your Mexican provider uses it: three questions

What must be in writing Patching the remote access tool is not a favor from the provider. It is part of the service.

Send them an email today, in English or Spanish. A good provider answers within minutes.

  • Which ScreenConnect version do you run, and is it patched?
  • Is it on-premise or cloud? If on-premise, who updated it and when?
  • Did you review sessions and extensions after the advisory?

If the answer is “let me check” and three days go by, you have your answer.

How to confirm the access did not stay open

One agent, one key A second remote access tool nobody installed means somebody already has their own way in.

Patching closes today’s door. You still need to check whether someone left a window open.

Ask the provider, or check yourself, that each PC has only one remote access agent: theirs. Two different tools means somebody else installed their own. Look for new local accounts with admin rights. And be suspicious of any “technician” calling your Mexico staff this week asking for urgent remote access. The flaw is the perfect excuse, as we explain in fake IT support calls via Teams and Quick Assist.

ProcessBi remote support
Not sure which tool runs on your Mexico PCs? We check it with you Foto: Pexels

What about your Mexico operation?

At ProcessBi our support plans include keeping remote access tools patched and auditing who connected, when and to which device. It is the least visible part of remote IT support in Mexico, and the one that matters most in a week like this.

If you do not know which tool runs on your Mexico PCs or who holds the key, that is where we start, with a free assessment.

Tell us about your site — we reply the same business day.

Your path

Running IT in Mexico from abroad

18 of 32
  1. Smart hands ✓ Read You are here 2 min
  2. Remote support ✓ Read You are here 3 min
  3. Nearshoring checklist ✓ Read You are here 2 min
  4. Retail rollouts ✓ Read You are here 2 min
  5. Fake IT support ✓ Read You are here 3 min
  6. Backups that restore ✓ Read You are here 3 min
  7. Secure M365 ✓ Read You are here 3 min
  8. Windows 10 deadline ✓ Read You are here 4 min
  9. Audit app access ✓ Read You are here 3 min
  10. CEO fraud ✓ Read You are here 4 min
  11. Office 2016 cutoff ✓ Read You are here 3 min
  12. Patch today ✓ Read You are here 4 min
  13. Patch VMware ✓ Read You are here 4 min
  14. Office 2021 EOL ✓ Read You are here 3 min
  15. Starlink for sites ✓ Read You are here 3 min
  16. Cardless access ✓ Read You are here 4 min
  17. Control AI on PCs ✓ Read You are here 4 min
  18. ScreenConnect flaw ✓ Read You are here 4 min
  19. Server 2022 EOL ✓ Read You are here 3 min
  20. Exposed cameras ✓ Read You are here 3 min
  21. Domain trust fix ✓ Read You are here 4 min
  22. Patch Cisco ISE ✓ Read You are here 3 min
  23. Protect the plant ✓ Read You are here 3 min
  24. Move to 25H2 ✓ Read You are here 4 min
  25. Outages and UPS ✓ Read You are here 3 min
  26. IT maintenance ✓ Read You are here 4 min
  27. Third-party scripts ✓ Read You are here 3 min
  28. License audit ✓ Read You are here 4 min
  29. Bajío fiber corridor ✓ Read You are here 3 min
  30. Check Point flaw ✓ Read You are here 4 min
  31. Cashless payments ✓ Read You are here 3 min
  32. AI that hacks alone ✓ Read You are here 3 min
  33. Field services
Next Windows Server 2022 leaves mainstream support on October 13, 2026: what changes and how to plan the move to Server 2025 for your Mexico operation