Summary
ConnectWise ScreenConnect is being actively exploited in attacks through CVE-2026-84869, a critical-severity missing authorization and improper privilege management vulnerability rated CVSS 9.9. The flaw allows an attacker with basic privileges in an active ScreenConnect remote session to transfer and execute arbitrary files on the ScreenConnect client system without authorization or confirmation from the host user. CISA added CVE-2026-84869 to its Known Exploited Vulnerabilities catalog on September 11 and set a federal remediation deadline of September 14, 2026. Huntress has confirmed three incidents in which threat actors used ScreenConnect to distribute malicious VBScript payloads to newly connected systems. Shadowserver is tracking more than 1,000 ScreenConnect instances that remain unpatched and internet-exposed. The vulnerability is patched in ScreenConnect 26.6.5 and later. Since 2024, CISA has flagged four ScreenConnect vulnerabilities as actively exploited, two of which were used in ransomware attacks.
Timeline
| Date | Event |
|---|---|
| Sep 7, 2026 | ConnectWise discloses CVE-2026-84869; advises administrators to disable TransferFiles permissions as temporary mitigation |
| Sep 11, 2026 | CISA adds CVE-2026-84869 to KEV catalog; sets September 14 federal remediation deadline; flags for forensic triage under BOD 26-04 |
| Sep 14, 2026 | Federal remediation deadline passes; active exploitation confirmed |
| Sep 16-17, 2026 | Huntress publishes confirmation of three incidents with VBScript payloads; Shadowserver tracks 1,000+ unpatched exposed instances |
What Happened
CVE-2026-84869 exists in the ScreenConnect client component, not the server. The vulnerability allows a party with an established remote session to execute arbitrary files on the client system without triggering the normal host confirmation prompt. In the three incidents Huntress confirmed, attackers used this capability to drop and execute malicious VBScript payloads on newly connected systems, likely as a staging step for follow-on intrusion activity.
Remote monitoring and management tools occupy a structurally privileged position in enterprise networks: they are intentionally allowed through firewalls, run with elevated system-level access, and are trusted by endpoint detection tools. CISA’s forensic triage requirement under BOD 26-04 reflects this: organizations should not treat patching as the sole response but should determine whether any ScreenConnect sessions conducted while the vulnerability was unpatched involved unauthorized file activity.
A temporary workaround is available: deselecting the TransferFiles permission in Administration > Security > Roles blocks the exploitation vector. Patching to 26.6.5 or later remains the definitive remediation.
Domain Intelligence
connectwise.com — 61.23
connectwise.com scores in the low-trust range at 61.23. ConnectWise is the vendor of the affected ScreenConnect product and the party that patched CVE-2026-84869 and provided temporary mitigation guidance. One threat intelligence source has flagged connectwise.com but the observation has not been independently corroborated.
The Trust Observatory · thetrustobservatory.com · September 17, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026