FR
live
Security Critical

ScreenConnect patches CVE-2026-84869, a missing-authorization flaw already exploited in live sessions

On September 8, 2026, ConnectWise shipped a fix for CVE-2026-84869, a missing authorization (CVSS 9.9) that lets an attacker push and run files on a machine during an active ScreenConnect session without host confirmation. Upgrade the client to version 26.6.5, then audit past sessions and file transfers before remote access becomes the entry point into your fleet.

Two dark computer screens joined by a cable whose one end glows amber, a luminous arrow crossing the link.

September 8, 2026. ConnectWise publishes a security bulletin and patches a flaw in ScreenConnect. September 11. CISA adds CVE-2026-84869 to its KEV catalog on the basis of confirmed active exploitation. September 14. The remediation deadline set by Binding Operational Directive 26-04 lapses for US federal agencies. Why it matters: the flaw allows an attacker to transfer and execute files on a machine during a live remote-support session without the user confirming — inside the very tool MSPs use to administer thousands of endpoints.

A missing authorization in the client, not the server

CVE-2026-84869 is a textbook access-control weakness: it pairs CWE-862 (Missing Authorization) with CWE-269 (Improper Privilege Management) for a CVSS 9.9 score. In practice, a low-privileged authenticated attacker can bypass the confirmation prompts on file operations. During an active ScreenConnect session, they become able to push a file to the remote endpoint and execute it without the host user approving anything.

The decisive detail is where the flaw lives: in the client, not the server. Remediation is therefore not just a matter of updating the ScreenConnect instance, but of reinstalling or upgrading the host clients and access agents deployed across every managed machine. A patched server still driving vulnerable clients leaves the door open — the legitimate session becomes the attack’s delivery channel.

The version to deploy is 26.6.5 or later. ConnectWise rates the issue priority 1 — “High” — the level reserved for vulnerabilities that are already targeted or at high risk of being targeted. No public exploit was documented at the time of the bulletin, but the KEV entry confirms the exploitation is real, not theoretical.

Why a remote-access tool is a special target

ScreenConnect occupies a singular position in a network: it is the trust infrastructure through which a provider or IT team reaches endpoints. Compromising this tool does not grant access to one machine, but to every system managed from the same console — what the literature calls a “one-to-many” risk. In an MSP environment, a single compromised ScreenConnect instance can become the pivot into dozens or hundreds of clients.

Attackers know this mechanic well. Remote-access and remote monitoring tools (RMM) rank among the most exploited vectors of recent years, precisely because they offer a legitimate path to code execution: an attacker abusing an active session shows up in the logs as normal administrative activity. The ScreenConnect flaw sits squarely in that lineage, and its fix illustrates the rule that follows — an RMM is hardened like a critical asset, not like a convenience tool.

KEV, BOD 26-04, and the forensic triage obligation

The KEV addition by CISA on September 11, 2026 carries two distinct operational consequences. The first is the deadline: US federal civilian agencies covered by BOD 26-04 had to remediate by September 14, 2026. The second, less visible, is the forensic triage requirement: CISA explicitly flags that patching is not enough, and that the organization must look for signs of compromise.

That requirement translates into a concrete checklist worth following regardless of whether you are a federal agency. Determine whether the ScreenConnect instance was internet-exposed; identify the hosts and sessions potentially affected; review file-transfer logs and process-execution records for abnormal activity; and inspect administrative accounts as well as active and historical sessions. Where suspicion arises, credential resets and session-token invalidation are the next move.

What an operator should do

The response breaks down into four ordered actions, the first being the only one that cuts the vector at the root.

  • Upgrade the client to 26.6.5 or later, then reinstall or upgrade the host clients and access agents on every managed endpoint. A patched server does not protect vulnerable clients.
  • Restrict network access to the ScreenConnect instance to trusted management subnets. An authorization flaw is only exploitable if the attacker can reach the session; segmentation shrinks that surface.
  • Audit the logs: unexpected file transfers, child processes launched through ScreenConnect, outbound connections from the service hosts, recently created or modified accounts. CISA recommends reviewing active and historical sessions.
  • Treat compromise as possible, not as proven. The absence of a public exploit does not mean the absence of exploitation — the KEV entry says otherwise. Rotate secrets and revoke tokens at the first doubt.

CVE-2026-84869 joins an already long line of remote-access vulnerabilities — from N-able N-central to MikroTik RouterOS, CISA added six flaws to the KEV catalog between September 10 and 11, 2026 alone, also touching GitLab and JFrog Artifactory. The underlying message is the same for all of them: the management perimeter has become attackers’ preferred hunting ground, and an RMM patch can no longer wait for the monthly cycle.

Verdict

CVE-2026-84869 is this week’s clearest demonstration that a remote-access tool gets patched like a critical asset and audited like an attack surface. If you run ScreenConnect, the absolute priority is 26.6.5 on servers and clients, followed by a file-transfer audit — do not stop at the server, because the client is what is vulnerable. If you are an MSP, treat every managed client as inheriting your console’s risk: document segmentation, limit internet exposure, and keep a register of deployed versions. If you do not expose your RMM to the internet, you have already made the cheapest and most effective choice — the flaw needs an active session to be exploited, and a tool confined to a management subnet is out of reach for most attackers.

References

cve

Linked vulnerabilities

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

← Back to the feed

Type at least two characters.

navigate open esc dismiss