ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security
Part of a story covered by 3 sources: “ConnectWise patches critical ScreenConnect flaw CVE-2026-84869 exploited in worm-like attacks” — merged summary and timeline →

ConnectWise security advisory (AV26-903)

highAdvisory exploited in the wildimportance 72CVE-2026-84869
AI summary · glm-5.3-flash

ConnectWise patches ScreenConnect CVE-2026-84869, reported exploited in the wild; administrators should update to 26.6.5.

ConnectWise shipped ScreenConnect 26.6.5 to fix a vulnerability tracked as CVE-2026-84869 affecting versions prior to 26.6.5. Open-source reporting indicates the flaw is being exploited in the wild. The Canadian Centre for Cyber Security issued advisory AV26-903 urging users and administrators to apply the patch.

  • CVE-2026-84869 affects ScreenConnect versions prior to 26.6.5.
  • Open-source reporting indicates exploitation in the wild.
  • Fix is available in ScreenConnect 26.6.5.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-84869
Missing authorization in ScreenConnect client allows unauthorized file execution

CVE-2026-84869 is a critical authorization flaw (CWE-862 missing authorization, CWE-269 improper privilege management) in the ScreenConnect client, the endpoint-side agent of ConnectWise's widely used remote access and remote support platform, in which files can be transferred to a machine and executed during an active remote session without the expected authorization or without confirmation by the Host (technician). It is triggered in certain circumstances during an active session, with a network attack vector, low attack complexity, low privileges required, and no user interaction per the CVSS 3.1 vector. An actor who obtains or already holds access to a session context could thereby push and run files on the managed endpoint, potentially achieving code execution with high confidentiality, integrity, and availability impact (CVSS 3.1 score 9.9, scope changed). Only endpoints running the ScreenConnect client are affected; ScreenConnect servers are not impacted, and the affected client version ranges are governed by ConnectWise security advisory AV26-903 (not enumerated in the available data). The flaw is not currently known to be exploited: it is not in CISA KEV, no public proof of concept is known, and EPSS assigns a modest 0.4% probability of exploitation within the next 30 days (32nd percentile).

Do: Follow ConnectWise security advisory AV26-903 and update ScreenConnect clients to the patched version it specifies, noting that ScreenConnect servers do not require remediation. Until patching is complete, monitor active remote sessions, require Host confirmation for file transfers, and review recent sessions on high-value endpoints for unexpected transferred or executed files; given no known exploitation and the active-session prerequisite, prioritize endpoints routinely accessed remotely.

9.9<1% KEV
  • ConnectWise ScreenConnect client (endpoint agent)
massplausibly millions of managed endpoints running the ScreenConnect client agent
Full article68 words · extracted from cyber.gc.ca · click to collapse

Serial number: AV26-903
Date: September 9, 2026

As of September 8, 2026, ConnectWise is affected by a vulnerability in the following product:

  • ScreenConnect
    • versions prior to 26.6.5

Open-source reporting indicates that CVE-2026-84869 is being exploited in the wild.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/connectwise-security-advisory-av26-903