SOCLYDE logo
Current languageEN
Cybersecurity newsScreenConnectConnectWiseCVE

Screenconnect: cve-2026-84869 is being actively exploited

CISA added CVE-2026-84869 to its KEV catalog after attacks targeting ScreenConnect. Here is the scope, the 26.6.5 fix, and the priority actions.

By Soclyde Team

Technician disabling file transfer on a remote support workstation

In summary

  • CVE-2026-84869 can, in certain circumstances, transfer and execute files through an active ScreenConnect session without authorization or Host confirmation.
  • The flaw affects ScreenConnect versions before 26.6.5; ConnectWise says servers are not impacted, but clients and access agents must be updated.
  • CISA added the vulnerability to its KEV catalog on September 11, 2026: deploy 26.6.5 and temporarily disable TransferFiles if deployment must wait.

Explore next

Soclyde resources

Article contents

On September 16, 2026, BleepingComputer reported that attackers were actively exploiting CVE-2026-84869, a ConnectWise ScreenConnect vulnerability added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 11. The flaw affects how ScreenConnect clients handle file transfers and can bypass an expected authorization step during an active remote session.

ConnectWise released the 26.6.5 update on September 8. The operational distinction matters for teams running the product: older versions need to be fixed quickly, while the vendor’s advisory distinguishes the ScreenConnect client from the servers themselves. The sources reviewed do not establish a specific compromise of a named customer; the documented risk is active exploitation.

What CISA and public sources confirmed

CVE-2026-84869 is now tracked as an actively exploited vulnerability. BleepingComputer links that status to CISA’s KEV addition and reports that the agency instructed U.S. federal agencies to secure their systems within a short deadline. The Canadian Centre for Cyber Security also confirms the September 11 KEV addition and points to public reporting of in-the-wild exploitation.

That status changes the operational priority. This is no longer only a vulnerability to schedule in the next maintenance cycle. For an organisation using ScreenConnect to troubleshoot, patch, or administer endpoints, an older instance should be treated as an access surface requiring immediate attention, even without evidence of compromise.

What CVE-2026-84869 enables

ConnectWise describes a missing-authorization and improper-privilege-management condition in the ScreenConnect client. In certain circumstances, an attacker with basic privileges can transfer and execute a file through an active remote session without the required authorization or Host confirmation. The advisory rates the attack as low complexity and requiring no user interaction in the assessed scenario.

ConnectWise published a 9.9 CVSS score. That score describes potential impact to confidentiality, integrity, and availability; it does not prove that a particular file was executed on every endpoint. An investigation should therefore separate what the flaw makes possible, what CISA confirms about active exploitation, and what still needs to be established locally.

Who is affected

ConnectWise says ScreenConnect versions before 26.6.5 are affected. The bulletin places the issue in the client and says ScreenConnect servers are not impacted by this vulnerability. Cloud and on-premise deployments appear in the mitigation advisory’s scope, but the remediation steps differ by deployment model.

For an on-premise partner, the priority is to install ScreenConnect 26.6.5 or a later version supported by the licence. For a cloud customer, ConnectWise says no server action is required; however, host clients should be reinstalled and access agents updated after the service upgrade. The inventory must therefore cover endpoints and agents, not only the administration URL.

Immediate actions for administrators

The recommended fix is to upgrade to ScreenConnect 26.6.5. If a change window or production freeze prevents immediate deployment, ConnectWise recommends clearing the TransferFiles permission for every session group and role under Administration > Security > Roles. In older versions, the permission may be named TransferFilesInSession.

This is a temporary exposure reduction, not a patch. After updating, review roles, session groups, host clients, and access agents so that no endpoint remains on a vulnerable version. Record the correction time and the systems covered; that evidence makes it easier to investigate activity that occurred before the update.

Checks after exposure

Teams that operated an older version should review connection logs, remote sessions, and file-transfer or execution events around the exposure window. Unusual filenames, an out-of-process session, an agent appearing without a ticket, or unexpected outbound traffic are signals to correlate, not isolated proof.

If malicious use is suspected, isolate affected endpoints without destroying evidence, preserve logs, and review the associated accounts and sessions. Revoke credentials or tokens that may have been exposed and check other remote-administration tools on the same machines. CISA and ConnectWise document the vulnerability, but the sources reviewed do not publish a customer list that would support claiming a specific organisation was compromised.

How Soclyde fits

Soclyde does not patch ScreenConnect, monitor remote sessions, or replace incident response. Its role is around secret-reuse risk: generate a unique password for each service, keep it in a local-first encrypted vault, and make rotation easier when an administrative account must be revoked or replaced.

That separation reduces the impact of reusing one secret across a remote-access tool, email, and other services. It does not make a compromised endpoint safe: patching, log review, session revocation, and agent control remain the priorities for ScreenConnect.

Key takeaways

CVE-2026-84869 is being actively exploited and affects ScreenConnect versions before 26.6.5. Teams should deploy the update, or temporarily clear TransferFiles across all roles if deployment must wait, then review clients and agents after remediation.

The right response is not to wait for an alert in your own environment: inventory deployments, search for transfer and execution events, and prepare to rotate associated access. To reduce secret reuse, read the secure password generator guide or contact Soclyde.

Frequently asked questions

Who needs to apply the ScreenConnect 26.6.5 update?

Partners running an on-premise installation should upgrade ScreenConnect to 26.6.5 or later. For cloud deployments, ConnectWise says no server action is required, but recommends reinstalling host clients and updating access agents after the service upgrade.

Is disabling TransferFiles enough?

No. ConnectWise describes disabling TransferFiles, or TransferFilesInSession in older versions, as a temporary measure when the update cannot be applied immediately. It reduces exposure but does not replace installing 26.6.5.

What should I check if a ScreenConnect instance was vulnerable?

Preserve session and authentication logs, look for unexpected transfers or executions, and review endpoints reachable from the instance. If compromise is suspected, isolate affected machines, revoke exposed sessions and credentials, and involve your incident-response team.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading