CISA Flags ScreenConnect Flaw Exploited Since August
Want more insights like this?
CISA added CVE-2026-84869, a ConnectWise ScreenConnect flaw rated CVSS 9.9 (Critical), to its Known Exploited Vulnerabilities catalog on September 11, 2026. Missing authorization and improper privilege management let an attacker transfer files to a device and execute them during an active remote session, with no host confirmation.
Huntress observed exploitation from August 20, three weeks before the KEV listing, so the forensic window opens there rather than at the catalog date. Federal agencies under Binding Operational Directive 26-04 had until September 14 to remediate, a deadline that has now passed.
ConnectWise fixed the flaw in ScreenConnect 26.6.5 on September 8. On-premises servers must already run 25.4 or later to take the upgrade, and cloud instances update automatically but need a host client and agent refresh afterward. If you cannot patch, revoke the TransferFiles permission. Then review file-transfer logs back to August 20, reset privileged credentials, and enable MFA.
Source: Cybersecurity News