ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
ConnectWise patched critical ScreenConnect flaw CVE-2026-84869 (CVSS 9.9) exploited since August 20 in worm-like attacks; CISA added it to KEV.
ConnectWise released urgent patches for CVE-2026-84869 (CVSS 9.9), a missing authorization and improper privilege management flaw in ScreenConnect allowing file transfer and execution through active remote sessions without host confirmation. Huntress reported in-the-wild exploitation since August 20, with attackers using rogue ScreenConnect clients to push four VBScript files for persistence and worm-like propagation to other ScreenConnect clients. The flaw is fixed in ScreenConnect 26.6.5, with disabling the TransferFiles permission as a temporary mitigation. CISA added the CVE to its KEV catalog, requiring federal agencies to patch within three days under BOD 26-04.
- CVE-2026-84869 scores 9.9/10 and enables unauthorized file transfer and execution via active sessions
- Exploited in the wild since August 20 in worm-like attacks spreading between ScreenConnect clients
- Fixed in ScreenConnect 26.6.5; temporary mitigation is disabling TransferFiles permission
- CISA added to KEV catalog with three-day federal patching deadline
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-84869 | Missing authorization in ScreenConnect client allows unauthorized file execution CVE-2026-84869 is a critical authorization flaw (CWE-862 missing authorization, CWE-269 improper privilege management) in the ScreenConnect client, the endpoint-side agent of ConnectWise's widely used remote access and remote support platform, in which files can be transferred to a machine and executed during an active remote session without the expected authorization or without confirmation by the Host (technician). It is triggered in certain circumstances during an active session, with a network attack vector, low attack complexity, low privileges required, and no user interaction per the CVSS 3.1 vector. An actor who obtains or already holds access to a session context could thereby push and run files on the managed endpoint, potentially achieving code execution with high confidentiality, integrity, and availability impact (CVSS 3.1 score 9.9, scope changed). Only endpoints running the ScreenConnect client are affected; ScreenConnect servers are not impacted, and the affected client version ranges are governed by ConnectWise security advisory AV26-903 (not enumerated in the available data). The flaw is not currently known to be exploited: it is not in CISA KEV, no public proof of concept is known, and EPSS assigns a modest 0.4% probability of exploitation within the next 30 days (32nd percentile). Do: Follow ConnectWise security advisory AV26-903 and update ScreenConnect clients to the patched version it specifies, noting that ScreenConnect servers do not require remediation. Until patching is complete, monitor active remote sessions, require Host confirmation for file transfers, and review recent sessions on high-value endpoints for unexpected transferred or executed files; given no known exploitation and the active-session prerequisite, prioritize endpoints routinely accessed remotely. | 9.9 | <1% | KEV |
| massplausibly millions of managed endpoints running the ScreenConnect client agent |
Full article395 words · extracted from securityweek.com · click to collapse
ConnectWise has released urgent patches for a critical-severity vulnerability in the ScreenConnect remote access and support software that has been exploited in worm-like attacks.
Tracked as CVE-2026-84869 (CVSS score of 9.9/10), the security defect is described as a missing authorization and improper privilege management issue.
The bug creates “a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances,” ConnectWise explains in its advisory.
In early September, cybersecurity firm Huntress warned that the vulnerability has been exploited in the wild since August 20.
As part of the observed incidents, a modified ScreenConnect instance was used to deploy four VBScript files designed to establish persistence and propagate to other ScreenConnect clients.
The hackers used social engineering to trick victims into executing rogue ScreenConnect clients, which then checked for active sessions to push the VBScript payload to connected targets.
Advertisement. Scroll to continue reading.
ConnectWise resolved the flaw in ScreenConnect version 26.6.5 and urged users to apply the fixes as soon as possible. As a temporary mitigation, it recommends disabling the TransferFiles permission in ScreenConnect.
“The ScreenConnect 26.6.5 patch includes updates to strengthen client and session handling for file-transfer and file-execution actions,” ConnectWise notes.
On Friday, the US cybersecurity agency CISA added CVE-2026-84869 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, as mandated by BOD 26-04.
Related: BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Related: GitLab Vulnerability Exploited One Day After Disclosure
Ionut Arghire is an international correspondent for SecurityWeek.
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.
In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/connectwise-patches-screenconnect-vulnerability-exploited-in-worm-like-attacks/