Critical ScreenConnect flaw under active exploitation: what to do if your Mexico operation or its IT provider uses this remote access tool
On September 16, 2026, BleepingComputer reported that a critical flaw in ConnectWise ScreenConnect is now being actively exploited in attacks. Not a theoretical advisory: someone is walking through that door today.
If you run a plant, warehouse or office in Mexico from abroad, this one lands close. ScreenConnect is the tool your local IT provider, or your own help desk back home, most likely uses to reach the PCs in Monterrey or Querétaro without flying anyone in.
What ScreenConnect is and why it matters even if you never installed it
A remote access tool leaves a small program on every PC, the agent, that waits for an authorized technician to connect. That is why the accountant in your Mexico office does nothing when someone fixes their Excel: a technician connects, sees the screen and sorts it out.
A critical flaw in that tool means whoever exploits it may end up holding the same key as your technician, on every machine at once. In our experience, an attacker who arrives through the provider’s tool does not look like an intruder. They look like support.
There are two ways to run ScreenConnect. On-premise means the server sits in your company or your provider’s, and a person has to patch it by hand. Cloud means ConnectWise hosts and updates it. Which one you have changes everything this week.
If the instance is yours: patch today
If your headquarters IT team runs its own ScreenConnect server to reach Mexico, the order is:
- Update to the fixed version ConnectWise lists. Today, not Friday.
- Review the session history for the last few days. Look for connections at odd hours, from countries where you have nobody, or to PCs nobody reported as broken.
- Check the extensions installed on the server. One nobody remembers adding is a red flag.
- Rotate admin passwords and turn on a second factor if it was off.
- If something looks wrong, do not delete it. Isolate the machine and get help. Evidence matters.
How to find the agent on the PCs in Mexico
Many foreign managers do not know which tool the local provider uses. Here is how to check without calling anyone. A screenshot from the site is enough.
| Where to look | What to look for |
|---|---|
| Control Panel, Programs | “ScreenConnect Client” followed by a long code |
| Windows Services | A service starting with ScreenConnect Client |
| Tray next to the clock | A small ConnectWise or ScreenConnect icon |
| Mac, Applications or Activity Monitor | “ScreenConnect Client” or “connectwisecontrol” process |
Write down the code. It identifies which server that agent reports to, so your provider knows exactly which instance to check.
If your Mexican provider uses it: three questions
Send them an email today, in English or Spanish. A good provider answers within minutes.
- Which ScreenConnect version do you run, and is it patched?
- Is it on-premise or cloud? If on-premise, who updated it and when?
- Did you review sessions and extensions after the advisory?
If the answer is “let me check” and three days go by, you have your answer.
How to confirm the access did not stay open
Patching closes today’s door. You still need to check whether someone left a window open.
Ask the provider, or check yourself, that each PC has only one remote access agent: theirs. Two different tools means somebody else installed their own. Look for new local accounts with admin rights. And be suspicious of any “technician” calling your Mexico staff this week asking for urgent remote access. The flaw is the perfect excuse, as we explain in fake IT support calls via Teams and Quick Assist.
What about your Mexico operation?
At ProcessBi our support plans include keeping remote access tools patched and auditing who connected, when and to which device. It is the least visible part of remote IT support in Mexico, and the one that matters most in a week like this.
If you do not know which tool runs on your Mexico PCs or who holds the key, that is where we start, with a free assessment.
Tell us about your site — we reply the same business day.
Your path
Running IT in Mexico from abroad
18 of 32- Smart hands ✓ Read You are here 2 min
- Remote support ✓ Read You are here 3 min
- Nearshoring checklist ✓ Read You are here 2 min
- Retail rollouts ✓ Read You are here 2 min
- Fake IT support ✓ Read You are here 3 min
- Backups that restore ✓ Read You are here 3 min
- Secure M365 ✓ Read You are here 3 min
- Windows 10 deadline ✓ Read You are here 4 min
- Audit app access ✓ Read You are here 3 min
- CEO fraud ✓ Read You are here 4 min
- Office 2016 cutoff ✓ Read You are here 3 min
- Patch today ✓ Read You are here 4 min
- Patch VMware ✓ Read You are here 4 min
- Office 2021 EOL ✓ Read You are here 3 min
- Starlink for sites ✓ Read You are here 3 min
- Cardless access ✓ Read You are here 4 min
- Control AI on PCs ✓ Read You are here 4 min
- ScreenConnect flaw ✓ Read You are here 4 min
- Server 2022 EOL ✓ Read You are here 3 min
- Exposed cameras ✓ Read You are here 3 min
- Domain trust fix ✓ Read You are here 4 min
- Patch Cisco ISE ✓ Read You are here 3 min
- Protect the plant ✓ Read You are here 3 min
- Move to 25H2 ✓ Read You are here 4 min
- Outages and UPS ✓ Read You are here 3 min
- IT maintenance ✓ Read You are here 4 min
- Third-party scripts ✓ Read You are here 3 min
- License audit ✓ Read You are here 4 min
- Bajío fiber corridor ✓ Read You are here 3 min
- Check Point flaw ✓ Read You are here 4 min
- Cashless payments ✓ Read You are here 3 min
- AI that hacks alone ✓ Read You are here 3 min
- Field services →