Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-84869 2026-09-11

CVE-2026-84869: ConnectWise ScreenConnect Client Flaw Allows Unauthorized File Transfer and Execution

"CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog on 2026-09-11, confirming active exploitation of a critical (CVSS 9.9) ConnectWise ScreenConnect client vulnerability that may permit file…"

CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog on 2026-09-11, confirming active exploitation of a critical (CVSS 9.9) ConnectWise ScreenConnect client vulnerability that may permit file transfer and execution during an active remote session without authorization or Host confirmation in certain circumstances.

What Is It

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. CISA classifies it as an improper privilege management (CWE-269) and missing authorization (CWE-862) vulnerability. ScreenConnect servers are not impacted; the flaw lies in the client.

The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H: network-reachable, low attack complexity, low privileges required, no user interaction, with a changed scope and high confidentiality, integrity, and availability impact.

Why It Matters

CISA's SSVC assessment marks exploitation as active, technical impact as total, and automatable as no. KEV inclusion confirms this is being exploited in the wild, not theorized. Known ransomware campaign use is listed as Unknown.

The KEV entry flags forensic triage as required, meaning affected organizations should assume compromise is possible and collect evidence rather than simply patching over it. Where the conditions for the flaw are met, execution occurs through a legitimate active remote session without Host confirmation, and an attacker operating within that session could gain code execution on the endpoint with no visible approval step.

What's Vulnerable

Patch Status

Fixed in ScreenConnect 26.6.5 (build 26.6.5.9742) per the vendor bulletin dated 2026-09-08.

CISA's required action, due 2026-09-14, is to apply mitigations in accordance with vendor instructions, ensuring compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines.

Sources