<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ConnectWise on PhllapsNET</title>
    <link>https://www.phllaps.net/tags/connectwise/</link>
    <description>Recent content in ConnectWise on PhllapsNET</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <lastBuildDate>Fri, 11 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.phllaps.net/tags/connectwise/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability</title>
      <link>https://www.phllaps.net/posts/connectwise-screenconnect-improper-privilege-management-and-missing-authorization-vulnerability/</link>
      <pubDate>Fri, 11 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/connectwise-screenconnect-improper-privilege-management-and-missing-authorization-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.9&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.9 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-09-11) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Fixed in &lt;code&gt;26.6.5.9742&lt;/code&gt;&lt;/strong&gt; — upgrade to this release or later.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-84869.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-84869 affects the ScreenConnect client, not the server component. ConnectWise describes it as a combination of improper privilege management and missing authorization: an active remote support session can be used to transfer and execute files without the host confirming or authorising that action first.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
