CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog on 2026-09-11, confirming active exploitation of a critical (CVSS 9.9) ConnectWise ScreenConnect client vulnerability that may permit file transfer and execution during an active remote session without authorization or Host confirmation in certain circumstances.
What Is It
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. CISA classifies it as an improper privilege management (CWE-269) and missing authorization (CWE-862) vulnerability. ScreenConnect servers are not impacted; the flaw lies in the client.
The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H: network-reachable, low attack complexity, low privileges required, no user interaction, with a changed scope and high confidentiality, integrity, and availability impact.
Why It Matters
CISA's SSVC assessment marks exploitation as active, technical impact as total, and automatable as no. KEV inclusion confirms this is being exploited in the wild, not theorized. Known ransomware campaign use is listed as Unknown.
The KEV entry flags forensic triage as required, meaning affected organizations should assume compromise is possible and collect evidence rather than simply patching over it. Where the conditions for the flaw are met, execution occurs through a legitimate active remote session without Host confirmation, and an attacker operating within that session could gain code execution on the endpoint with no visible approval step.
What's Vulnerable
- Vendor/Product: ConnectWise ScreenConnect (client)
- Affected versions: all versions prior to 26.6.5 (CPE match:
versionEndExcluding 26.6.5.9742) - Not affected: ScreenConnect servers
Patch Status
Fixed in ScreenConnect 26.6.5 (build 26.6.5.9742) per the vendor bulletin dated 2026-09-08.
CISA's required action, due 2026-09-14, is to apply mitigations in accordance with vendor instructions, ensuring compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines.
Sources
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869
- NVD, CVE-2026-84869, https://nvd.nist.gov/vuln/detail/CVE-2026-84869
- ConnectWise Security Bulletin (2026-09-08), https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin
- ConnectWise Trust Advisories; https://www.connectwise.com/company/trust/advisories
- ConnectWise-Advisories Disclosures (GitHub), https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-84869
- Huntress, Rogue ScreenConnect Installations, https://www.huntress.com/blog/rogue-screenconnect-installations
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk