ConnectWise released an emergency security patch today to address a critical ConnectWise ScreenConnect vulnerability. The severe flaw allows unauthorized attackers to transfer and execute malicious files during active remote sessions. CISA officially added the bug to its Known Exploited Vulnerabilities catalog following evidence of active exploitation in the wild.
- CVE: CVE-2026-84869
- CVSS: 9.9 (Critical · CVSSv3)
- Product: ConnectWise ScreenConnect
- Affected: All versions prior to 26.6.5
- Impact: ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
- Status: Exploited in the wild
- EPSS: 0.4% (30-day)
- Action: See vendor advisory
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy This Threat Matters
Thousands of managed service providers use ScreenConnect to support remote client networks. Therefore, a compromise of this central tool creates massive supply chain risks. If attackers exploit this ConnectWise ScreenConnect vulnerability, they can pivot directly into downstream corporate environments. Threat actors use these remote access footholds to deploy ransomware or steal confidential business data.
How the Attack Works
The vulnerability involves weak authorization checks within the client component. Specifically, the software improperly controls file transfer permissions during active sessions. An attacker can bypass the intended role-based access controls and push malicious files directly to the host machine. After transferring the payload, the attacker can execute the file without requiring elevated privileges.
Affected Versions
This severe file transfer vulnerability impacts all unpatched on-premise ScreenConnect installations. ConnectWise confirmed active exploitation in the wild. The flaw carries a near-maximum CVSS base score of 9.9.
Patch and Mitigation Steps
Administrators must upgrade their servers immediately. The vendor released ScreenConnect 26.6.5 to fix the authorization logic. You can review the upgrade instructions in the official ConnectWise security bulletin. Furthermore, CISA issued an alert regarding the threat on its Known Exploited Vulnerabilities catalog update.
If immediate patching is impossible, you can apply a temporary mitigation. The vendor advises administrators to navigate to the security settings and edit every role. Administrators must explicitly deselect the TransferFiles permission across all session groups. After upgrading or applying mitigations, teams must also reinstall host clients to ensure complete protection.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!