LATEST View all updates

ScreenConnect CVE-2026-84869: Check 26.6.5 and Client Updates

Check which ScreenConnect versions are affected, what 26.6.5 fixes, and what cloud and on-prem admins must update.

Remote support security illustration showing client and access-agent updates for ScreenConnect CVE-2026-84869

Signal Brief

  • ConnectWise says ScreenConnect versions before 26.6.5 are affected by CVE-2026-84869; version 26.6.5 or later is the fixed state.
  • The flaw affects ScreenConnect client/session behavior, while ConnectWise says the ScreenConnect server itself is not impacted by this specific condition.
  • Cloud and on-prem administrators should verify host clients and access agents are updated instead of assuming a service or server upgrade alone proves full remediation.
  • Removing TransferFiles permissions is a temporary mitigation when immediate upgrading is impossible, not a replacement for the 26.6.5+ security update.

ScreenConnect CVE-2026-84869 patch guidance now has a clear fixed-version boundary: ConnectWise says ScreenConnect versions before 26.6.5 are affected, while remediation is available in version 26.6.5 or later. The important administrator check is not only the server or service version. ConnectWise separately tells customers to refresh host clients and update access agents, so a deployment should not be treated as fully remediated until those endpoint components are also brought into the corrected state.

ConnectWise describes CVE-2026-84869 as a client-side authorization and privilege-management issue that can, under certain circumstances, allow files to be transferred and executed through an active remote session without authorization or Host confirmation. The vendor says the ScreenConnect server itself is not impacted by this specific flaw.

Which ScreenConnect versions are affected by CVE-2026-84869?

ConnectWise says ScreenConnect versions before 26.6.5 are affected. Version 26.6.5 or later is the vendor-defined remediated state.

The vulnerability carries a CVSS v3.1 base score of 9.9. ConnectWise classifies the bulletin as Priority 1 — High. That priority label should not be read as proof that ConnectWise has confirmed active exploitation of this specific CVE.

Is ScreenConnect 26.6.5 the fixed version?

Yes. ConnectWise states that remediation is available in ScreenConnect 26.6.5 or later. Administrators running an older on-premises version should move to 26.6.5 or a later supported release rather than relying indefinitely on the temporary mitigation.

Does CVE-2026-84869 affect the ScreenConnect server?

ConnectWise says the ScreenConnect server component is not impacted by this specific condition. The flaw concerns ScreenConnect client/session behavior.

That distinction does not mean an on-premises administrator can ignore the security update. ConnectWise still directs on-premises customers to upgrade the product so the corrected client/session handling can be deployed, and it separately calls for host-client and access-agent updates.

What should on-premises ScreenConnect administrators do?

Check the installed version

If the ScreenConnect deployment is earlier than 26.6.5, it falls inside the vendor-defined affected range.

Upgrade to 26.6.5 or later

Apply the current supported security update rather than treating the temporary permission mitigation as a permanent fix.

Refresh host clients

Follow ConnectWise guidance to reinstall or refresh host clients after the product update.

Update access agents

Verify that deployed access agents have also moved to the remediated client state.

What should ScreenConnect cloud customers check?

ConnectWise says its cloud deployments have been updated. Cloud customers should still verify the endpoint side of the remediation by making sure host clients are reinstalled or refreshed and access agents are updated.

A cloud-side service update should therefore not be interpreted as proof that every previously deployed endpoint component has already refreshed successfully.

What if ScreenConnect 26.6.5 cannot be installed immediately?

ConnectWise provides a temporary mitigation for organizations that cannot upgrade immediately: remove the TransferFiles permission, including the legacy TransferFilesInSession permission where applicable, from relevant user roles or session groups.

This reduces exposure to the vulnerable file-transfer path but is not equivalent to installing the security update. The preferred final state remains ScreenConnect 26.6.5 or later with the required client and agent refreshes completed.

How can an administrator verify the environment is actually remediated?

Server or service state

Confirm the ScreenConnect deployment is on 26.6.5 or later, or that the ConnectWise cloud service has received the vendor update.

Host-client state

Confirm host clients have been refreshed or reinstalled as directed by ConnectWise.

Access-agent state

Check that access agents have updated instead of assuming the server-side upgrade automatically proves endpoint remediation.

Temporary mitigation state

If file-transfer permissions were removed as an interim measure, keep track of that configuration until the permanent update path is complete.

Is CVE-2026-84869 actively exploited?

TPS did not establish a clean ConnectWise confirmation that CVE-2026-84869 itself is being actively exploited. ConnectWise’s Priority 1 classification covers vulnerabilities that are being targeted or have a higher risk of being targeted, so the label alone does not prove CVE-specific exploitation.

Huntress has reported suspicious ScreenConnect-related activity across multiple organizations and later discussed CVE-2026-84869 in that investigation context. That is relevant threat evidence, but TPS does not treat all observed ScreenConnect abuse as confirmed exploitation of this exact vulnerability without stronger attribution.

Is CVE-2026-84869 in CISA KEV?

TPS did not establish a current CISA Known Exploited Vulnerabilities listing for CVE-2026-84869 during this review. Because KEV status can change quickly, administrators should verify the current CISA catalog rather than relying on a permanent statement from this article.

What should security teams do after patching?

If an organization has evidence of suspicious remote sessions, unexpected file transfers, unauthorized access or other compromise indicators, patching should not be treated as proof that the environment was never compromised. Incident-response decisions should follow current ConnectWise guidance and the organization’s own security evidence.

TPS is not asserting that every vulnerable ScreenConnect deployment requires compromise remediation. The need for investigation depends on the organization’s observed activity, logs and future vendor or incident-response guidance.

What happens next?

The most important state changes to monitor are a ConnectWise exploitation confirmation, a CISA KEV addition, revised affected-version guidance, a superseding fixed release, or publication of CVE-specific compromise-hunting instructions. Those developments should update this same URL while the reader job remains verifying and completing remediation for CVE-2026-84869.

Verification note: TPS reviewed ConnectWise’s ScreenConnect security bulletin and advisory, the CVE record, NHS cyber guidance and current incident-response reporting. The affected-version boundary, 26.6.5 remediation, client-side scope, cloud/on-prem actions and temporary permission mitigation are supported by the vendor. CVE-specific exploitation attribution remains unresolved.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led informational and editorial guidance on ScreenConnect CVE-2026-84869. ConnectWise confirms the affected-version and remediation state, but CVE-specific real-world exploitation, victim scope and current CISA KEV status were not established in the reviewed evidence. Verify the latest ConnectWise security bulletin and current authoritative security guidance before consequential remediation or incident-response decisions.