Published September 15, 2026 - Tampa, FL. ConnectWise disclosed CVE-2026-84869 on September 8, 2026, a 9.9 CVSS critical vulnerability in ScreenConnect 26.6.5 and earlier that allows guest-to-host file execution without authorization or Host confirmation. CISA added the CVE to the KEV catalog with active exploitation confirmed.
Data last verified September 15, 2026 from ConnectWise security bulletin, CVE.org CVE-2026-84869 record, and CISA KEV catalog.
ScreenConnect CVE-2026-84869 is a 9.9 CVSS critical flaw patched in ScreenConnect 26.6.5 on September 8, 2026. Servers not affected; client only. Priority 1 High. Update immediately or strip TransferFiles permission. Last verified: Sep 15, 2026.
At a glance
- CVE: CVE-2026-84869
- Severity: 9.9 CVSS Critical, Priority 1 High, Important severity
- Vulnerability type: CWE-862 (Missing Authorization) + CWE-269 (Improper Privilege Management)
- Affected: ScreenConnect client versions prior to 26.6.5
- Not affected: ScreenConnect servers
- Patch: ScreenConnect 26.6.5 (Sep 8, 2026)
- Mitigation: Strip TransferFiles permission from roles
- Active exploitation: confirmed, CISA KEV added
How the ScreenConnect flaw works
The vulnerability allows a guest user to transfer and execute files through an active remote session without authorization or Host confirmation in certain circumstances. The Host believes the session is benign but files are being transferred and executed.
ScreenConnect is a remote access and support tool used by MSPs and IT departments worldwide. In a typical session, a Host grants temporary access to a guest (technician) for support purposes. The Host can authorize or deny file transfer and file execution actions during the session. CVE-2026-84869 bypasses this authorization check under specific conditions, allowing the guest to perform file operations without the Host's knowledge or consent. The flaw does not require authentication beyond having access to the session (ConnectWise security bulletin, September 8, 2026; CWE-862 documentation).
CVSS breakdown
CVE-2026-84869 receives a CVSS 3.1 base score of 9.9 (Critical). The vector and impact metrics drive the critical score.
| CVSS metric | Value | Score contribution |
|---|---|---|
| Attack Vector (AV) | Network | Exploitable remotely |
| Attack Complexity (AC) | Low | No special conditions needed |
| Required Privileges (PR) | Low | Any guest with active session |
| User Interaction (UI) | None | No Host action required |
| Scope (S) | Changed | Affects Host system beyond ScreenConnect |
| Confidentiality (C) | High | Full read access via file execution |
| Integrity (I) | High | Full write access via file execution |
| Availability (A) | High | Can install ransomware, wipers, or other destructive payloads |
Source: CVE.org CVE-2026-84869 CVSS calculator; ConnectWise security bulletin, September 8, 2026.
Patching the ScreenConnect flaw
ScreenConnect 26.6.5 is the patched version released September 8, 2026. Apply the update as an emergency change.
| Patch step | Action | Time required | Notes |
|---|---|---|---|
| 1. Update ScreenConnect server | Administration > Updates > Install 26.6.5 | 15-30 minutes | Server not affected but should be updated |
| 2. Wait for client propagation | Clients auto-update within 24-72 hours | 1-3 days | Verify via client version report |
| 3. Audit recent sessions | Review session logs for file operations | 1-2 hours | Look for unauthorized transfers |
| 4. Verify TransferFiles permissions | Roles > Permissions > Confirm TransferFiles status | 30 minutes | Even after patch, restrict by default |
Source: ConnectWise security bulletin, September 8, 2026; ConnectWise update documentation, September 2026.
Temporary mitigation if patching is delayed
Removing the TransferFiles permission from all roles is the recommended temporary mitigation until the patch is applied. This reduces the attack surface without removing remote access.
| Mitigation step | Action | Effect |
|---|---|---|
| 1. Navigate to roles | Administration > Security > Roles | Open role configuration |
| 2. Edit each role | Select role, click Edit | Access permission settings |
| 3. Deselect TransferFiles | Uncheck TransferFiles permission | Disable file transfer capability |
| 4. Save changes | Save role configuration | Apply to all sessions using this role |
| 5. Repeat for each role | Apply to all roles in the system | Full mitigation across organization |
Source: ConnectWise security bulletin mitigation section, September 8, 2026.
ScreenConnect in the broader MSP security context
ScreenConnect and similar remote access tools have become high-value targets for threat actors because they provide direct access to MSP-managed endpoints. A single ScreenConnect compromise can give attackers access to hundreds or thousands of customer systems.
The 2024 ScreenConnect mass-exploitation campaign affected over 2,000 organizations in a single wave. The 2025 ConnectWise Automate RCE vulnerabilities were exploited by ransomware operators including LockBit and BlackCat. The September 2026 CVE-2026-84869 continues this pattern. MSPs using ScreenConnect should adopt a security-first posture: apply all patches within 48 hours, restrict default permissions, enable session recording for audit, and use MFA for technician access (ConnectWise security advisories, 2024-2026; CrowdStrike MSP threat analysis, 2026).
Detection and IoCs
Three IoC patterns indicate possible ScreenConnect exploitation. Detection requires session log review.
| Indicator | Source log | Detection method |
|---|---|---|
| File transfer events without Host approval | ScreenConnect session logs | Audit log filtering |
| Unexpected process spawning on Host post-session | Endpoint EDR | Process tree analysis |
| Outbound network connections from ScreenConnect process | Endpoint EDR, network logs | Connection monitoring |
Source: ConnectWise security bulletin IoC list, September 8, 2026; CrowdStrike ScreenConnect detection guidance, September 2026.
FAQs
The questions above cover what CVE-2026-84869 is, how severe the flaw is, which versions are affected, how to patch it, temporary mitigation if patching is delayed, and how to detect exploitation.






