CISA Warns of Critical ScreenConnect Vulnerability Actively Exploited in Attacks
CISA added actively exploited ConnectWise ScreenConnect flaw CVE-2026-84869 to the KEV catalog, setting a September 14 patch deadline.
CISA added CVE-2026-84869, a critical improper privilege management and missing authorization flaw (CWE-269, CWE-862) in ConnectWise ScreenConnect, to its Known Exploited Vulnerabilities Catalog on September 11, 2026, confirming active exploitation. The flaw lets attackers transfer files to a device and execute them during an active remote ScreenConnect session without authorization or host-user confirmation, enabling payload delivery, unauthorized tools, and persistence while blending into legitimate remote-management traffic. CISA set a September 14 remediation deadline under BOD 26-04 and flagged the vulnerability as requiring forensic triage. ConnectWise has published a security bulletin, and defenders are urged to review exposure, sessions, file-transfer records, and outbound connections.
- CISA confirmed active exploitation and added CVE-2026-84869 to KEV on September 11, 2026.
- Flaw allows unauthorized file transfer and execution during active ScreenConnect remote sessions.
- Mapped to CWE-269 Improper Privilege Management and CWE-862 Missing Authorization.
- BOD 26-04 remediation deadline September 14, 2026; forensic triage required beyond patching.
- RMM compromise risk is amplified because ScreenConnect often manages multiple client environments.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-84869 | Missing authorization in ScreenConnect client allows unauthorized file execution CVE-2026-84869 is a critical authorization flaw (CWE-862 missing authorization, CWE-269 improper privilege management) in the ScreenConnect client, the endpoint-side agent of ConnectWise's widely used remote access and remote support platform, in which files can be transferred to a machine and executed during an active remote session without the expected authorization or without confirmation by the Host (technician). It is triggered in certain circumstances during an active session, with a network attack vector, low attack complexity, low privileges required, and no user interaction per the CVSS 3.1 vector. An actor who obtains or already holds access to a session context could thereby push and run files on the managed endpoint, potentially achieving code execution with high confidentiality, integrity, and availability impact (CVSS 3.1 score 9.9, scope changed). Only endpoints running the ScreenConnect client are affected; ScreenConnect servers are not impacted, and the affected client version ranges are governed by ConnectWise security advisory AV26-903 (not enumerated in the available data). The flaw is not currently known to be exploited: it is not in CISA KEV, no public proof of concept is known, and EPSS assigns a modest 0.4% probability of exploitation within the next 30 days (32nd percentile). Do: Follow ConnectWise security advisory AV26-903 and update ScreenConnect clients to the patched version it specifies, noting that ScreenConnect servers do not require remediation. Until patching is complete, monitor active remote sessions, require Host confirmation for file transfers, and review recent sessions on high-value endpoints for unexpected transferred or executed files; given no known exploitation and the active-session prerequisite, prioritize endpoints routinely accessed remotely. | 9.9 | <1% | KEV |
| massplausibly millions of managed endpoints running the ScreenConnect client agent |
Full article480 words · extracted from cybersecuritynews.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical ConnectWise ScreenConnect vulnerability, tracked as CVE-2026-84869, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming that threat actors are actively exploiting the flaw in attacks.
The issue affects ScreenConnect, a widely used remote monitoring and support platform that enables administrators and managed service providers to access endpoints remotely.
CVE-2026-84869 is an improper privilege management and missing authorization vulnerability. In practical terms, the flaw could allow an attacker to transfer files to a device and execute them during an active remote ScreenConnect session without obtaining authorization or receiving confirmation from the host user.
The vulnerability is mapped to CWE-269, Improper Privilege Management, and CWE-862, Missing Authorization. The flaw is particularly significant because remote-access tools occupy a trusted position in many enterprise networks.
ScreenConnect Vulnerability Exploited
If an attacker can abuse an active session, they may deliver malicious payloads, run unauthorized tools, establish persistence, or move deeper into an affected environment while appearing to use legitimate remote-management infrastructure.
Such platforms are frequently targeted because a compromise can provide access to multiple managed systems, especially in environments supported by IT service providers.
CISA added CVE-2026-84869 to the KEV Catalog on September 11, 2026, and set a remediation deadline of September 14, 2026, for organizations covered by Binding Operational Directive 26-04.
The agency also flagged the vulnerability as requiring forensic triage under the directive, indicating that affected organizations should not treat patching as the sole response.
Security teams should determine whether ScreenConnect instances were internet-exposed, identify potentially affected hosts and sessions, and review available logs for suspicious file-transfer or execution activity.
ConnectWise has published a security bulletin addressing the ScreenConnect issue and provides vendor guidance for mitigation.
Organizations should apply the vendor’s recommended fixes immediately, validate that every ScreenConnect server and managed endpoint is covered, and restrict external access wherever possible.
According to the advisory catalog published by CISA, CISA advised stakeholders to assess each asset’s internet exposure and follow BOD 26-04 risk-based update requirements; where mitigations are unavailable, organizations should discontinue use of the affected product.
Defenders should also review ScreenConnect administrative accounts, active and historical remote sessions, file-transfer records, child processes launched through ScreenConnect, and outbound connections from systems hosting the service.
Credential resets and session-token invalidation may be appropriate where suspicious activity is detected. While CISA’s entry does not identify confirmed ransomware use, active exploitation means organizations should assume that opportunistic and targeted attackers may rapidly incorporate the vulnerability into intrusion workflows.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/screenconnect-vulnerability-exploited/