DIRAS TAKE
Urgent: this CVE was added to CISA’s Known Exploited Vulnerabilities catalog with a short remediation deadline (2026-09-14), so prioritize mitigation for internet-facing and high-value ScreenConnect instances immediately.
What is CVE-2026-84869?
An attacker with an active ScreenConnect remote session can transfer and execute files on a client without host confirmation, potentially leading to full compromise. CVE-2026-84869 affects all ScreenConnect versions prior to 26.6.5 and requires an attacker to have an active remote session (low privilege) rather than network-only access; servers are not impacted. The issue is an improper privilege management/missing authorization flaw that allows file operations and execution during a live session under certain circumstances.
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Which versions of ConnectWise ScreenConnect are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| ScreenConnect | All versions prior to 26.6.5 |
Is CVE-2026-84869 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-11; US federal agencies were required to address it by 2026-09-14.
How to fix CVE-2026-84869
- Restrict ScreenConnect access to trusted networks and VPNs and block internet exposure where feasible.
- Disable or restrict file transfer and remote file execution features in ScreenConnect client settings if configurable.
- Apply vendor guidance and mitigations as published by ConnectWise and monitor their advisories for an official patch.
- Increase logging and monitor remote session activity for unexpected file transfers or execution; isolate affected hosts if suspicious activity is detected.
Frequently asked questions
Is CVE-2026-84869 being actively exploited?
CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog on 2026-09-11; federal agencies were required to remediate by 2026-09-14.
Which ScreenConnect versions are affected by CVE-2026-84869?
All ConnectWise ScreenConnect versions prior to 26.6.5 are affected.
Is there a patch for CVE-2026-84869?
No patch is listed in the supplied facts; ConnectWise has not published fixed versions in the provided data.
Does CVE-2026-84869 require authentication?
The issue requires an active ScreenConnect remote session (low-privilege authenticated session) to transfer and execute files on the client.
References
- nvd.nist.gov/vuln/detail/CVE-2026-84869
- cve.org/CVERecord?id=CVE-2026-84869
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869
- connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin
- github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-84869
- connectwise.com/company/trust/advisories
- All ConnectWise CVEs on CVE Radar
- CVEs published in September 2026