ConnectWise patches critical ScreenConnect flaw CVE-2026-84869 exploited in worm-like attacks
ConnectWise fixed critical ScreenConnect flaw CVE-2026-84869 (CVSS 9.9) in version 26.6.5; Huntress reported exploitation since August 20 in worm-like attacks, and CISA added the CVE to its KEV catalog with a three-day federal patching deadline.
ConnectWise released ScreenConnect 26.6.5 to patch CVE-2026-84869, a critical flaw (CVSS 9.9) affecting versions prior to 26.6.5. SecurityWeek describes it as a missing authorization and improper privilege management flaw, while CSO Online characterizes it as an authentication failure; both agree it enables unauthorized file transfer and execution through active remote sessions without host confirmation. ConnectWise warned customers on September 3, and the patch arrived five days later; administrators were advised to remove or disable the TransferFiles permission from users with open sessions as an interim mitigation. Huntress reported in-the-wild exploitation since August 20, with attackers using rogue ScreenConnect clients to push four VBScript files for persistence and worm-like propagation to other ScreenConnect clients. Sources disagree on exploitation status: CSO Online notes that ConnectWise's own advisory did not state exploitation had been observed, while the Canadian Centre for Cyber Security (advisory AV26-903) and SecurityWeek cite in-the-wild exploitation reporting. CISA added the CVE to its KEV catalog, requiring federal agencies to patch within three days under BOD 26-04.
- CVE-2026-84869 affects ScreenConnect versions prior to 26.6.5 and is fixed in version 26.6.5
- CVSS score of 9.9/10
- Flaw allows unauthorized file transfer and execution through active remote sessions without host confirmation
- ConnectWise warned customers on September 3; patch released five days later
- Interim mitigation: remove or disable the TransferFiles permission from users with open sessions
- Huntress reported in-the-wild exploitation since August 20 in worm-like attacks using rogue ScreenConnect clients that push four VBScript files for persistence and propagation to other ScreenConnect clients
- CISA added CVE-2026-84869 to its KEV catalog with a three-day federal patching deadline under BOD 26-04
- Canadian Centre for Cyber Security issued advisory AV26-903 urging users and administrators to apply the patch
Coverage timelineoldest first · each row is one article
- · 6d agoConnectWise security advisory (AV26-903)
Canadian Centre for Cyber Security· 72
ConnectWise patches ScreenConnect CVE-2026-84869, reported exploited in the wild; administrators should update to 26.6.5.
- · 4d agoConnectWise patches critical ScreenConnect authentication failure after five days
CSO Online· 66
ConnectWise patched ScreenConnect flaw CVE-2026-84869 five days after warning files could be transferred and executed via active sessions without authorization.
- · 1d agoConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
SecurityWeek· 90
ConnectWise patched critical ScreenConnect flaw CVE-2026-84869 (CVSS 9.9) exploited since August 20 in worm-like attacks; CISA added it to KEV.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-84869 | Missing authorization in ScreenConnect client allows unauthorized file execution CVE-2026-84869 is a critical authorization flaw (CWE-862 missing authorization, CWE-269 improper privilege management) in the ScreenConnect client, the endpoint-side agent of ConnectWise's widely used remote access and remote support platform, in which files can be transferred to a machine and executed during an active remote session without the expected authorization or without confirmation by the Host (technician). It is triggered in certain circumstances during an active session, with a network attack vector, low attack complexity, low privileges required, and no user interaction per the CVSS 3.1 vector. An actor who obtains or already holds access to a session context could thereby push and run files on the managed endpoint, potentially achieving code execution with high confidentiality, integrity, and availability impact (CVSS 3.1 score 9.9, scope changed). Only endpoints running the ScreenConnect client are affected; ScreenConnect servers are not impacted, and the affected client version ranges are governed by ConnectWise security advisory AV26-903 (not enumerated in the available data). The flaw is not currently known to be exploited: it is not in CISA KEV, no public proof of concept is known, and EPSS assigns a modest 0.4% probability of exploitation within the next 30 days (32nd percentile). Do: Follow ConnectWise security advisory AV26-903 and update ScreenConnect clients to the patched version it specifies, noting that ScreenConnect servers do not require remediation. Until patching is complete, monitor active remote sessions, require Host confirmation for file transfers, and review recent sessions on high-value endpoints for unexpected transferred or executed files; given no known exploitation and the active-session prerequisite, prioritize endpoints routinely accessed remotely. | 9.9 | <1% | KEV |
| massplausibly millions of managed endpoints running the ScreenConnect client agent |