<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

CISA Flags ScreenConnect Flaw Exploited Since August

Attackers have abused CVE-2026-84869 since August 20 to run files on remote-session hosts. Upgrade to ScreenConnect 26.6.5 and revoke TransferFiles.
Content Team

CISA added CVE-2026-84869, a ConnectWise ScreenConnect flaw rated CVSS 9.9 (Critical), to its Known Exploited Vulnerabilities catalog on September 11, 2026. Missing authorization and improper privilege management let an attacker transfer files to a device and execute them during an active remote session, with no host confirmation.

Huntress observed exploitation from August 20, three weeks before the KEV listing, so the forensic window opens there rather than at the catalog date. Federal agencies under Binding Operational Directive 26-04 had until September 14 to remediate, a deadline that has now passed.

ConnectWise fixed the flaw in ScreenConnect 26.6.5 on September 8. On-premises servers must already run 25.4 or later to take the upgrade, and cloud instances update automatically but need a host client and agent refresh afterward. If you cannot patch, revoke the TransferFiles permission. Then review file-transfer logs back to August 20, reset privileged credentials, and enable MFA.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo