ScreenConnect CVE-2026-84869 is now a confirmed actively exploited vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on September 11, 2026. That materially changes the administrator task: organizations should still patch ScreenConnect to version 26.6.5 or later and refresh the relevant clients and access agents, but patching alone is no longer enough to close the question. Systems that were exposed while vulnerable should also be reviewed for signs of compromise.
ConnectWise describes CVE-2026-84869 as a client-side authorization and privilege-management issue that can, under certain circumstances, allow files to be transferred and executed through an active remote session without authorization or Host confirmation. ConnectWise says the ScreenConnect server itself is not impacted by this specific flaw.
Is CVE-2026-84869 actively exploited?
Yes. CISA added CVE-2026-84869 to its Known Exploited Vulnerabilities catalog on September 11, 2026. A KEV listing means CISA has evidence that the vulnerability has been exploited in the wild.
The CISA catalog lists September 14, 2026 as the remediation due date for federal civilian agencies subject to the applicable directive and marks forensic triage as required under the current KEV handling framework. CISA’s catalog also shows the ransomware-use status as unknown, so active exploitation should not be converted into a claim that this CVE is confirmed to be part of ransomware campaigns.
Which ScreenConnect versions are affected?
ConnectWise says ScreenConnect versions before 26.6.5 are affected. Version 26.6.5 or later is the vendor-defined remediated state.
The vulnerability carries a CVSS v3.1 base score of 9.9. ConnectWise classifies the bulletin as Priority 1 — High and recommends installing the update as an emergency change or as soon as possible.
Is ScreenConnect 26.6.5 the fixed version?
Yes. ConnectWise states that remediation is available in ScreenConnect 26.6.5 or later. Administrators running an older on-premises version should move to 26.6.5 or a later supported release rather than relying indefinitely on the temporary mitigation.
Because exploitation is now confirmed, administrators should treat the fixed version as the minimum patch state, not as evidence that an environment was never compromised before the update.
Does CVE-2026-84869 affect the ScreenConnect server?
ConnectWise says the ScreenConnect server component is not impacted by this specific condition. The flaw concerns ScreenConnect client/session behavior.
That distinction does not mean an on-premises administrator can ignore the security update. ConnectWise still directs on-premises customers to upgrade the product so corrected client/session handling can be deployed, and it separately calls for host-client and access-agent updates.
What should on-premises ScreenConnect administrators do?
If the ScreenConnect deployment is earlier than 26.6.5, it falls inside the vendor-defined affected range.
Apply the current supported security update rather than treating the temporary permission mitigation as a permanent fix.
Follow ConnectWise guidance to reinstall or refresh host clients after the product update.
Verify that deployed access agents have also moved to the remediated client state.
What should ScreenConnect cloud customers check?
ConnectWise says its cloud deployments have been updated. Cloud customers should still verify the endpoint side of the remediation by making sure host clients are reinstalled or refreshed and access agents are updated.
A cloud-side service update should therefore not be interpreted as proof that every previously deployed endpoint component has already refreshed successfully or that prior exposure can be ignored.
What if ScreenConnect 26.6.5 cannot be installed immediately?
ConnectWise provides a temporary mitigation for organizations that cannot upgrade immediately: remove the TransferFiles permission, including the legacy TransferFilesInSession permission where applicable, from relevant user roles or session groups.
This reduces exposure to the vulnerable file-transfer path but is not equivalent to installing the security update. With active exploitation confirmed, organizations should not treat the mitigation as a reason to postpone the permanent update longer than operationally necessary.
How can an administrator verify the environment is patched?
Confirm the ScreenConnect deployment is on 26.6.5 or later, or that the ConnectWise cloud service has received the vendor update.
Confirm host clients have been refreshed or reinstalled as directed by ConnectWise.
Check that access agents have updated instead of assuming the server-side upgrade automatically proves endpoint remediation.
If file-transfer permissions were removed as an interim measure, keep track of that configuration until the permanent update path is complete.
Why patching is no longer the whole task
CISA’s KEV addition confirms exploitation in the wild. Patching prevents continued exposure to the known vulnerability, but it does not determine whether a vulnerable system was exploited before remediation.
Organizations that operated an affected ScreenConnect version should therefore separate two questions: Is the environment patched now? and Is there evidence that the environment was compromised while vulnerable?
What should security teams review for compromise?
Retain available ScreenConnect, endpoint, identity, network and security telemetry needed to reconstruct activity during the exposure period before routine retention or cleanup removes it.
ConnectWise recommends reviewing users with ScreenConnect access, removing unrecognized users and checking roles and permissions after patching.
ConnectWise also recommends changing passwords and enabling MFA as part of the post-patch security review.
Look for remote sessions, file transfers, execution activity or administrative changes that cannot be reconciled with authorized support operations.
Correlate ScreenConnect activity with endpoint and security telemetry for unexpected processes, files, persistence or follow-on remote-access activity.
If evidence indicates unauthorized activity, follow the organization’s incident-response process for containment, scoping, credential protection and forensic investigation.
CISA’s KEV entry marks forensic triage as required for federal agencies under the applicable directive. For other organizations, the KEV addition is still strong evidence that vulnerable internet-facing or otherwise exposed ScreenConnect environments deserve urgent patching and risk-based compromise review.
Does every vulnerable ScreenConnect deployment need a full incident response?
No blanket conclusion is supported. A vulnerable version establishes exposure to the flaw; it does not by itself prove successful exploitation in a particular environment.
The depth of compromise review should reflect the organization’s exposure, available telemetry, suspicious activity and incident-response requirements. An environment with unexplained remote sessions, file transfers, new accounts, unexpected executable activity or other anomalies warrants a different response from an environment with strong evidence showing no suspicious activity during the relevant period.
What does CISA KEV change for defenders?
Before the KEV addition, administrators could treat the primary verified task as completing ConnectWise’s remediation path. The current evidence now supports a stronger defensive posture: patch urgently, verify the client and agent state, and determine whether historical exposure requires compromise investigation.
For U.S. federal civilian agencies covered by the applicable CISA directive, the KEV catalog lists September 14, 2026 as the remediation due date and requires the specified forensic-triage handling. Other organizations are not automatically subject to that federal deadline, but CISA recommends that organizations use the KEV catalog to prioritize vulnerabilities known to be exploited.
What happens next?
The next material checkpoint is September 14, 2026, the remediation due date shown in CISA’s KEV catalog for affected federal civilian agencies. Security teams should also monitor ConnectWise and CISA for any CVE-specific hunting guidance, indicators, revised affected-version information, campaign attribution or further remediation instructions.
Verification note: TPS reviewed the ConnectWise ScreenConnect 26.6.5 security bulletin and advisory together with the current CISA Known Exploited Vulnerabilities state. ConnectWise confirms the affected-version boundary and remediation path; CISA now confirms exploitation in the wild. The existence of active exploitation does not prove that every vulnerable ScreenConnect environment was compromised.



