ScreenConnect Flaw CVE-2026-84869 Exploited in Attacks
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 11, with a September 14 remediation deadline for federal agencies. Its entry lists use in ransomware campaigns as unknown. The exploitation warning therefore does not establish that this particular flaw has been used to deploy ransomware.
ConnectWise identifies missing authorization and improper privilege management, with a CVSS 3.1 score of 9.9. Its advisory describes network exploitation requiring low privileges, with low attack complexity and no user interaction. Versions before 26.6.5 are affected; the vendor states that the vulnerability is in clients, while ScreenConnect servers are not impacted.
In its technical disclosure, ConnectWise explains that file-transfer actions in Support and Access sessions could pass through an active remote session without proper authorization or host confirmation. Under certain conditions, files could reach the host client and execute there, including through elevated execution actions.
ConnectWise directs on-premises customers to upgrade to ScreenConnect 26.6.5 or later. Cloud instances have already been updated, but partners should reinstall host clients and update access agents. When immediate patching is impractical, the vendor recommends temporarily removing TransferFiles permission from every applicable session group across all roles; this does not replace the update.
After patching, ConnectWise recommends reviewing users and permissions, removing unrecognized accounts, changing passwords and enabling multifactor authentication. CISA also directs affected organizations to follow vendor mitigations and its applicable forensic triage guidance, or discontinue use if mitigations are unavailable.