• CISA KEV
  • EXPLOITED

CVE-2026-84869: missing authorization in ConnectWise ScreenConnect

An attacker with an active ScreenConnect remote session can transfer and execute files on a client without host confirmation, potentially leading to full compromise. CVE-2026-84869 affects all ScreenConnect versions prior to 26.6.5 and requires an attacker to have an active remote session (low privilege) rather than network-only access; servers are not impacted. The issue is an improper privilege management/missing authorization flaw that allows file operations and execution during a live session under certain circumstances.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.9CRITICAL
EPSS
0.00924
CWE
CWE-862
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: this CVE was added to CISA’s Known Exploited Vulnerabilities catalog with a short remediation deadline (2026-09-14), so prioritize mitigation for internet-facing and high-value ScreenConnect instances immediately.

What is CVE-2026-84869?

An attacker with an active ScreenConnect remote session can transfer and execute files on a client without host confirmation, potentially leading to full compromise. CVE-2026-84869 affects all ScreenConnect versions prior to 26.6.5 and requires an attacker to have an active remote session (low privilege) rather than network-only access; servers are not impacted. The issue is an improper privilege management/missing authorization flaw that allows file operations and execution during a live session under certain circumstances.

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Which versions of ConnectWise ScreenConnect are affected?

BRANCHAFFECTEDFIXED
ScreenConnectAll versions prior to 26.6.5

Is CVE-2026-84869 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-11; US federal agencies were required to address it by 2026-09-14.

How to fix CVE-2026-84869

  1. Restrict ScreenConnect access to trusted networks and VPNs and block internet exposure where feasible.
  2. Disable or restrict file transfer and remote file execution features in ScreenConnect client settings if configurable.
  3. Apply vendor guidance and mitigations as published by ConnectWise and monitor their advisories for an official patch.
  4. Increase logging and monitor remote session activity for unexpected file transfers or execution; isolate affected hosts if suspicious activity is detected.

Frequently asked questions

Is CVE-2026-84869 being actively exploited?

CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog on 2026-09-11; federal agencies were required to remediate by 2026-09-14.

Which ScreenConnect versions are affected by CVE-2026-84869?

All ConnectWise ScreenConnect versions prior to 26.6.5 are affected.

Is there a patch for CVE-2026-84869?

No patch is listed in the supplied facts; ConnectWise has not published fixed versions in the provided data.

Does CVE-2026-84869 require authentication?

The issue requires an active ScreenConnect remote session (low-privilege authenticated session) to transfer and execute files on the client.

References