← Vulnerability feed

Vulnerability record · CVE-2026-84869 · published 8 September 2026

CVE-2026-84869: ScreenConnect client allows unauthorized file transfer and execution in remote sessions

Connectwise · Screenconnect

A flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host confirmation under certain circumstances. ScreenConnect servers are not affected, so exposure is limited to client endpoints participating in sessions. Because it bypasses the Host's approval step, it undermines the control that normally gates file transfer and execution during a support session.

9.9 CVSS 3.1 Critical CISA KEV since 11 Sep 2026 EPSS 0.92% · top 41.2% CWE-269 · Improper privilege managementCWE-862 · Missing authorization
9.9CVSS 3.1 base score
0.92%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
12 Sep 2026Last modified by NVD

Description

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.9 with scope change plus CISA KEV listing and a three-day federal remediation deadline indicate severe, actively exploited risk.

What it is

A flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host confirmation under certain circumstances. ScreenConnect servers are not affected, so exposure is limited to client endpoints participating in sessions. Because it bypasses the Host's approval step, it undermines the control that normally gates file transfer and execution during a support session.

Impact

An attacker in a position to act within a session can move and run files on the client host without the Host's consent, effectively gaining code execution on that endpoint. The changed scope and high confidentiality, integrity and availability ratings mean full compromise of the client machine is plausible.

Attack surface

Reached over the network through an active ScreenConnect remote session; the vector requires low privileges (PR:L) and no user interaction (UI:N). The description ties the flaw to session conditions rather than the server, so the client endpoint is the target.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2026-09-11 with a remediation due date of 2026-09-14, indicating known exploitation. EPSS is low (0.00691, ~51st percentile), and no ransomware campaign use is documented.

What to do

  • Apply the vendor fix per the ConnectWise ScreenConnect advisory and bulletin, prioritizing client endpoints.
  • If patching is not immediately possible, follow CISA BOD 26-04 guidance for cloud services or discontinue use of the product where mitigations are unavailable.
  • Restrict and monitor who can initiate or join remote sessions, and require explicit Host confirmation for file transfer and execution where configurable.
  • Review session and file-transfer logs for unauthorized transfers or executions and treat any confirmed case as a host compromise.
  • Inventory ScreenConnect client installations, including rogue or unmanaged ones, and remove those not needed for business use.

Detection

  • Alert on file transfer or process execution events in ScreenConnect sessions that lack a corresponding Host approval or confirmation.
  • Hunt for unexpected child processes spawned by the ScreenConnect client service on endpoints.
  • Monitor for rogue or unauthorized ScreenConnect client installations and sessions originating from unexpected hosts.
  • Correlate ScreenConnect session activity with endpoint file-write and execution telemetry around the same timeframe.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog on 11 September 2026 as "ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 14 September 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-84869 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-1709ConnectWise ScreenConnect authentication bypass via alternate pathConnectWise ScreenConnect 23.9.7 and earlier contain an authentication bypass (CWE-288) that lets an unauthenticated attacker reach protected functio…KEVEPSS 100%analysed8.4CVE-2024-1708ConnectWise ScreenConnect path traversal enabling remote code executionConnectWise ScreenConnect 23.9.7 and earlier contain a path-traversal flaw (CWE-22) that can let an attacker execute remote code or reach confidentia…KEVEPSS 95%analysed7.2CVE-2025-3935ScreenConnect ViewState code injection enables RCEScreenConnect 25.2.3 and earlier rely on ASP.NET ViewState protected by machine keys, and if those keys are compromised an attacker can craft a malic…KEVEPSS 3.5%analysed9.1CVE-2025-14265Connectwise screenconnect download of code without integrity check vulnerabilityIn versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation …EPSS 0.37%8.1CVE-2023-47257Connectwise automate code injection vulnerabilityConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.EPSS 1.0%5.5CVE-2023-47256Connectwise automate improper authentication vulnerabilityConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settingsEPSS 0.45%5.3CVE-2025-14823Connectwise screenconnect vulnerabilityIn deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could…EPSS 0.15%5.3CVE-2022-36781Connectwise screenconnect improper restriction of authentication attempts vulnerabilityConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate r…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2026-84869), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.