ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.9Security Advisory

TL;DR 📌

  • ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.
  • Highest CVSS: 9.9 (Critical).
  • Listed in CISA KEV (2026-09-11) — this is being exploited in the wild.
  • Fixed in 26.6.5.9742 — upgrade to this release or later.
  • CVEs: CVE-2026-84869.

What it is

CVE-2026-84869 affects the ScreenConnect client, not the server component. ConnectWise describes it as a combination of improper privilege management and missing authorization: an active remote support session can be used to transfer and execute files without the host confirming or authorising that action first.

The CVSS vector shows low attack complexity, no user interaction required, and a privilege requirement of “low” (PR:L), with network access sufficient to reach the flaw. The impact scores are high across confidentiality, integrity and availability, and the scope is changed — meaning the client-side issue can affect resources beyond the vulnerable component itself. In practice this points to an attacker who already has some foothold in an active remote session being able to push files onto the host and run them, bypassing the confirmation step that would normally require the host user’s consent.

ScreenConnect servers are explicitly stated as not impacted; the exposure sits in the client software used on the endpoints being remotely accessed or supported.

This CVE is listed in the CISA Known Exploited Vulnerabilities catalogue, added on 2026-09-11.

What to do

  • Update ScreenConnect clients to version 26.6.5.9742 or later, the fixed release named in the advisory.
  • Confirm the update applies specifically to the client component — ScreenConnect servers are not affected, so don’t delay client patching while waiting on server-side changes that aren’t needed.
  • Because this is in CISA KEV, treat patching as time-sensitive rather than routine; check internal patch-compliance tooling for any endpoints still running pre-26.6.5.9742 clients.
  • Review logs for remote sessions where file transfer occurred without an explicit host confirmation prompt, if your ScreenConnect deployment retains session/transfer logs, to help scope any prior exposure.
  • Consult the NVD advisory (CVE-2026-84869) directly for any further clarifications ConnectWise publishes, since no additional fixed-release detail beyond the version above is provided here.

For leadership 🧭

Executive summary. An attacker who has reached an active ScreenConnect remote session can transfer and execute files on the endpoint without the host’s approval, and this is already listed as a known exploited vulnerability. Patch the ScreenConnect client to 26.6.5.9742 or later as a priority, not on the routine patch cycle.

Why it matters:

  • The flaw sits in the ScreenConnect client used on endpoints being remotely supported, not in the ScreenConnect server, so server-side controls won’t stop it.
  • An active remote session can be used to transfer and execute files on the host without the confirmation prompt normally required from the host user, removing a key consent barrier.
  • The CVSS vector shows no user interaction and low attack complexity, with high impact to confidentiality, integrity and availability and a changed scope, meaning consequences can extend beyond the client itself.
  • This CVE is in the CISA Known Exploited Vulnerabilities catalogue, added 2026-09-11, which changes the urgency of remediation.

Now / Next / Later:

  • Now: Check patch-compliance tooling for any endpoints still running ScreenConnect clients older than 26.6.5.9742.
  • Next: Roll out the ScreenConnect client update to 26.6.5.9742 or later across all remotely supported endpoints, prioritising over routine patch scheduling given KEV status.
  • Later: Establish a standing process to monitor CISA KEV additions affecting remote-support tooling and to fast-track client-side patching separately from server-side release cycles.

Source