Vulnerability record · CVE-2026-84869 · published 8 September 2026
CVE-2026-84869: ScreenConnect client allows unauthorized file transfer and execution in remote sessions
Connectwise · Screenconnect
A flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host confirmation under certain circumstances. ScreenConnect servers are not affected, so exposure is limited to client endpoints participating in sessions. Because it bypasses the Host's approval step, it undermines the control that normally gates file transfer and execution during a support session.
Description
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.9 with scope change plus CISA KEV listing and a three-day federal remediation deadline indicate severe, actively exploited risk.
What it is
A flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host confirmation under certain circumstances. ScreenConnect servers are not affected, so exposure is limited to client endpoints participating in sessions. Because it bypasses the Host's approval step, it undermines the control that normally gates file transfer and execution during a support session.
Impact
An attacker in a position to act within a session can move and run files on the client host without the Host's consent, effectively gaining code execution on that endpoint. The changed scope and high confidentiality, integrity and availability ratings mean full compromise of the client machine is plausible.
Attack surface
Reached over the network through an active ScreenConnect remote session; the vector requires low privileges (PR:L) and no user interaction (UI:N). The description ties the flaw to session conditions rather than the server, so the client endpoint is the target.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2026-09-11 with a remediation due date of 2026-09-14, indicating known exploitation. EPSS is low (0.00691, ~51st percentile), and no ransomware campaign use is documented.
What to do
- Apply the vendor fix per the ConnectWise ScreenConnect advisory and bulletin, prioritizing client endpoints.
- If patching is not immediately possible, follow CISA BOD 26-04 guidance for cloud services or discontinue use of the product where mitigations are unavailable.
- Restrict and monitor who can initiate or join remote sessions, and require explicit Host confirmation for file transfer and execution where configurable.
- Review session and file-transfer logs for unauthorized transfers or executions and treat any confirmed case as a host compromise.
- Inventory ScreenConnect client installations, including rogue or unmanaged ones, and remove those not needed for business use.
Detection
- Alert on file transfer or process execution events in ScreenConnect sessions that lack a corresponding Host approval or confirmation.
- Hunt for unexpected child processes spawned by the ScreenConnect client service on endpoints.
- Monitor for rogue or unauthorized ScreenConnect client installations and sessions originating from unexpected hosts.
- Correlate ScreenConnect session activity with endpoint file-write and execution telemetry around the same timeframe.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog on 11 September 2026 as "ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 14 September 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-84869 | Third Party Advisory |
| https://www.connectwise.com/company/trust/advisories | Vendor Advisory |
| https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869 | US Government Resource |
| https://www.huntress.com/blog/rogue-screenconnect-installations | Third Party Advisory |
Track CVE-2026-84869 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-84869), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.