LATEST View all updates

ScreenConnect CVE-2026-84869 Exploited: Patch 26.6.5 and Check for Compromise

CISA now confirms exploitation of CVE-2026-84869. Patch ScreenConnect, refresh clients and review exposed systems for compromise.

Remote support security illustration showing client and access-agent updates for ScreenConnect CVE-2026-84869

Signal Brief

  • CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog on September 11, confirming exploitation in the wild.
  • ConnectWise says ScreenConnect versions before 26.6.5 are affected and version 26.6.5 or later is the remediated state.
  • Cloud and on-prem administrators should verify host clients and access agents are updated instead of assuming a service or server update proves full remediation.
  • Because exploitation is confirmed, affected organizations should treat patch verification and compromise review as separate tasks.

ScreenConnect CVE-2026-84869 is now a confirmed actively exploited vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on September 11, 2026. That materially changes the administrator task: organizations should still patch ScreenConnect to version 26.6.5 or later and refresh the relevant clients and access agents, but patching alone is no longer enough to close the question. Systems that were exposed while vulnerable should also be reviewed for signs of compromise.

ConnectWise describes CVE-2026-84869 as a client-side authorization and privilege-management issue that can, under certain circumstances, allow files to be transferred and executed through an active remote session without authorization or Host confirmation. ConnectWise says the ScreenConnect server itself is not impacted by this specific flaw.

Is CVE-2026-84869 actively exploited?

Yes. CISA added CVE-2026-84869 to its Known Exploited Vulnerabilities catalog on September 11, 2026. A KEV listing means CISA has evidence that the vulnerability has been exploited in the wild.

The CISA catalog lists September 14, 2026 as the remediation due date for federal civilian agencies subject to the applicable directive and marks forensic triage as required under the current KEV handling framework. CISA’s catalog also shows the ransomware-use status as unknown, so active exploitation should not be converted into a claim that this CVE is confirmed to be part of ransomware campaigns.

Which ScreenConnect versions are affected?

ConnectWise says ScreenConnect versions before 26.6.5 are affected. Version 26.6.5 or later is the vendor-defined remediated state.

The vulnerability carries a CVSS v3.1 base score of 9.9. ConnectWise classifies the bulletin as Priority 1 — High and recommends installing the update as an emergency change or as soon as possible.

Is ScreenConnect 26.6.5 the fixed version?

Yes. ConnectWise states that remediation is available in ScreenConnect 26.6.5 or later. Administrators running an older on-premises version should move to 26.6.5 or a later supported release rather than relying indefinitely on the temporary mitigation.

Because exploitation is now confirmed, administrators should treat the fixed version as the minimum patch state, not as evidence that an environment was never compromised before the update.

Does CVE-2026-84869 affect the ScreenConnect server?

ConnectWise says the ScreenConnect server component is not impacted by this specific condition. The flaw concerns ScreenConnect client/session behavior.

That distinction does not mean an on-premises administrator can ignore the security update. ConnectWise still directs on-premises customers to upgrade the product so corrected client/session handling can be deployed, and it separately calls for host-client and access-agent updates.

What should on-premises ScreenConnect administrators do?

Check the installed version

If the ScreenConnect deployment is earlier than 26.6.5, it falls inside the vendor-defined affected range.

Upgrade to 26.6.5 or later

Apply the current supported security update rather than treating the temporary permission mitigation as a permanent fix.

Refresh host clients

Follow ConnectWise guidance to reinstall or refresh host clients after the product update.

Update access agents

Verify that deployed access agents have also moved to the remediated client state.

What should ScreenConnect cloud customers check?

ConnectWise says its cloud deployments have been updated. Cloud customers should still verify the endpoint side of the remediation by making sure host clients are reinstalled or refreshed and access agents are updated.

A cloud-side service update should therefore not be interpreted as proof that every previously deployed endpoint component has already refreshed successfully or that prior exposure can be ignored.

What if ScreenConnect 26.6.5 cannot be installed immediately?

ConnectWise provides a temporary mitigation for organizations that cannot upgrade immediately: remove the TransferFiles permission, including the legacy TransferFilesInSession permission where applicable, from relevant user roles or session groups.

This reduces exposure to the vulnerable file-transfer path but is not equivalent to installing the security update. With active exploitation confirmed, organizations should not treat the mitigation as a reason to postpone the permanent update longer than operationally necessary.

How can an administrator verify the environment is patched?

Server or service state

Confirm the ScreenConnect deployment is on 26.6.5 or later, or that the ConnectWise cloud service has received the vendor update.

Host-client state

Confirm host clients have been refreshed or reinstalled as directed by ConnectWise.

Access-agent state

Check that access agents have updated instead of assuming the server-side upgrade automatically proves endpoint remediation.

Temporary mitigation state

If file-transfer permissions were removed as an interim measure, keep track of that configuration until the permanent update path is complete.

Why patching is no longer the whole task

CISA’s KEV addition confirms exploitation in the wild. Patching prevents continued exposure to the known vulnerability, but it does not determine whether a vulnerable system was exploited before remediation.

Organizations that operated an affected ScreenConnect version should therefore separate two questions: Is the environment patched now? and Is there evidence that the environment was compromised while vulnerable?

What should security teams review for compromise?

Preserve relevant evidence

Retain available ScreenConnect, endpoint, identity, network and security telemetry needed to reconstruct activity during the exposure period before routine retention or cleanup removes it.

Review users and permissions

ConnectWise recommends reviewing users with ScreenConnect access, removing unrecognized users and checking roles and permissions after patching.

Reset credentials and strengthen authentication

ConnectWise also recommends changing passwords and enabling MFA as part of the post-patch security review.

Review remote-session and file-transfer activity

Look for remote sessions, file transfers, execution activity or administrative changes that cannot be reconciled with authorized support operations.

Check affected endpoints

Correlate ScreenConnect activity with endpoint and security telemetry for unexpected processes, files, persistence or follow-on remote-access activity.

Escalate suspicious findings

If evidence indicates unauthorized activity, follow the organization’s incident-response process for containment, scoping, credential protection and forensic investigation.

CISA’s KEV entry marks forensic triage as required for federal agencies under the applicable directive. For other organizations, the KEV addition is still strong evidence that vulnerable internet-facing or otherwise exposed ScreenConnect environments deserve urgent patching and risk-based compromise review.

Does every vulnerable ScreenConnect deployment need a full incident response?

No blanket conclusion is supported. A vulnerable version establishes exposure to the flaw; it does not by itself prove successful exploitation in a particular environment.

The depth of compromise review should reflect the organization’s exposure, available telemetry, suspicious activity and incident-response requirements. An environment with unexplained remote sessions, file transfers, new accounts, unexpected executable activity or other anomalies warrants a different response from an environment with strong evidence showing no suspicious activity during the relevant period.

What does CISA KEV change for defenders?

Before the KEV addition, administrators could treat the primary verified task as completing ConnectWise’s remediation path. The current evidence now supports a stronger defensive posture: patch urgently, verify the client and agent state, and determine whether historical exposure requires compromise investigation.

For U.S. federal civilian agencies covered by the applicable CISA directive, the KEV catalog lists September 14, 2026 as the remediation due date and requires the specified forensic-triage handling. Other organizations are not automatically subject to that federal deadline, but CISA recommends that organizations use the KEV catalog to prioritize vulnerabilities known to be exploited.

What happens next?

The next material checkpoint is September 14, 2026, the remediation due date shown in CISA’s KEV catalog for affected federal civilian agencies. Security teams should also monitor ConnectWise and CISA for any CVE-specific hunting guidance, indicators, revised affected-version information, campaign attribution or further remediation instructions.

Verification note: TPS reviewed the ConnectWise ScreenConnect 26.6.5 security bulletin and advisory together with the current CISA Known Exploited Vulnerabilities state. ConnectWise confirms the affected-version boundary and remediation path; CISA now confirms exploitation in the wild. The existence of active exploitation does not prove that every vulnerable ScreenConnect environment was compromised.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

    Verification

    The KEV addition materially changes the evidence boundary but does not prove compromise of any individual deployment.

  2. Updated

    Reader-facing article content was materially updated.

    What changed

    CISA now confirms CVE-2026-84869 exploitation in the wild, so the current reader task is to complete the 26.6.5 remediation path and review previously exposed environments for compromise.

    Previous state

    ConnectWise had confirmed the fixed-version and client-update path, while CVE-specific active exploitation and CISA KEV status remained unresolved.

    Current state

    CISA KEV confirms active exploitation, while ConnectWise continues to require 26.6.5 or later plus host-client and access-agent remediation; affected organizations should also perform risk-based compromise review.

  3. Verified

    TPS completed a source-verification pass.

  4. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led informational and editorial guidance on ScreenConnect CVE-2026-84869. CISA now lists the vulnerability in its Known Exploited Vulnerabilities catalog, so affected organizations should treat patching and compromise review as separate tasks. The presence of an affected version does not prove an individual environment was compromised. Verify the latest CISA KEV entry, ConnectWise bulletin and your own security evidence before consequential remediation or incident-response decisions.