ScreenConnect patches CVE-2026-84869, a missing-authorization flaw already exploited in live sessions
On September 8, 2026, ConnectWise shipped a fix for CVE-2026-84869, a missing authorization (CVSS 9.9) that lets an attacker push and run files on a machine during an active ScreenConnect session without host confirmation. Upgrade the client to version 26.6.5, then audit past sessions and file transfers before remote access becomes the entry point into your fleet.