Summary
- CVE-2026-84869 can allow unauthorised file transfer and execution through an active ScreenConnect remote session in certain circumstances.
- CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 11 September.
- ConnectWise says ScreenConnect servers are not affected; cloud deployments have been updated, while on-premises customers need version 26.6.5 or later.
A ScreenConnect client vulnerability that can allow unauthorised file transfer and execution through an active remote session is being exploited in the wild, with the US government adding the flaw to its Known Exploited Vulnerabilities catalogue.
ConnectWise disclosed CVE-2026-84869 as an authorisation and privilege-management issue affecting ScreenConnect Remote Access Support and Access sessions. The company assigned the flaw a CVSS score of 9.9.
Under certain circumstances, the condition can allow files to be transferred and executed through an active remote session without authorisation or confirmation from the host. ConnectWise says ScreenConnect servers themselves are not affected.
The company released version 26.6.5 to address the issue. Cloud deployments have been upgraded automatically, while on-premises customers need to install version 26.6.5 or later and update relevant clients or access agents.
The US Cybersecurity and Infrastructure Security Agency added CVE-2026-84869 to its Known Exploited Vulnerabilities catalogue on 11 September. The entry establishes active exploitation but does not identify the attackers, affected organisations, or the scale of observed activity.
CISA also marks the vulnerability as requiring forensic triage under its current federal remediation framework and sets a 14 September due date for affected US federal systems. Its catalogue does not currently establish use in ransomware campaigns.
The exploitation finding matters because remote-management products occupy an unusually privileged position in enterprise environments. ScreenConnect is designed to provide administrators and support personnel with remote access to endpoints, meaning abuse can inherit capabilities that would otherwise require an attacker to establish separate remote-control tooling.
That does not make every recent malicious use of ScreenConnect evidence of CVE-2026-84869. Rogue ScreenConnect clients have recently been used to propagate malicious scripts, while separate phishing campaigns have persuaded users to install attacker-controlled ScreenConnect software. Those incidents relied on different mechanisms and should not be attributed to this vulnerability without evidence.
The distinction reflects the multiple ways legitimate remote-management software can enter an attack chain. An adversary may exploit a flaw in the product, steal valid credentials, compromise an existing administrator, or convince a victim to install an unauthorised client that functions exactly as designed.
CVE-2026-84869 concerns the first category: a security defect in file-transfer and execution handling during an active session. ConnectWise initially issued interim mitigation guidance before the final security update became generally available.
For on-premises environments unable to upgrade immediately, the company has described temporary mitigation involving removal of the TransferFiles permission from user roles. ConnectWise explicitly says that mitigation is not a substitute for installing the security update.
The split between hosted and self-managed deployments creates a familiar operational difference. A software provider can patch its cloud estate centrally, while organisations operating their own installations remain dependent on local asset inventories, maintenance windows, licensing position, and change-control processes.
Remote-support platforms can be particularly sensitive to those delays because their function is to reach other machines. A vulnerable administration tool is not necessarily equivalent to an exposed business application: the privileges and trusted connectivity built into the product can amplify the consequence of successful abuse.
The evidence now supports a bounded conclusion. CVE-2026-84869 is a critical client-side ScreenConnect vulnerability, ConnectWise has released a fixed version, and CISA says exploitation has occurred. Public sources reviewed for this article do not establish who is exploiting it or how broad the campaign has become.




