Opens in a new tab

ScreenConnect Vulnerability Exploited in Attacks

Actively exploited ScreenConnect flaw added to CISA KEV, urgent patching and triage advised

A critical ScreenConnect vulnerability is being actively exploited, according to the US Cybersecurity and Infrastructure Security Agency. Tracked as CVE-2026-84869, the flaw can allow files to be transferred and executed through an active remote session without host authorisation.

CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog on 11 September 2026. The listing confirms that exploitation has occurred in real attacks, making this an urgent incident response issue for organisations operating ConnectWise ScreenConnect.

ScreenConnect vulnerability added to CISA catalog

ScreenConnect is a remote monitoring and support platform used by administrators and managed service providers to access endpoints. This trusted access is central to the risk presented by CVE-2026-84869, because activity conducted through the platform may appear to originate from legitimate remote management infrastructure.

CISA classified the ScreenConnect vulnerability as a known exploited issue after confirming evidence of active exploitation. Inclusion in the catalog does not merely indicate that a proof of concept exists or that exploitation is theoretically possible. It means threat actors have used the flaw in practice.

The agency added CVE-2026-84869 to the catalog on 11 September 2026 and set 14 September 2026 as the remediation deadline for organisations covered by Binding Operational Directive 26-04. That deadline had already passed when the reported details were published on 16 September 2026.

CISA also marked the issue as requiring forensic triage under the directive. This is an important part of the warning because installing an update will not identify whether an attacker previously accessed a system, transferred a payload or established another route into the environment.

What is currently known about exploitation

CISA’s listing confirms that the ScreenConnect vulnerability is being exploited, but the available report does not name the threat actors involved, identify affected victims or quantify the number of attacks. It also does not describe a specific malware family or confirmed ransomware campaign linked to the flaw.

As of 16 September 2026, the information provided therefore establishes active exploitation without defining its full scale. Organisations should not interpret the absence of named victims or attack groups as evidence of limited impact.

The report does not provide a list of affected ScreenConnect version numbers. Administrators should consult ConnectWise’s security bulletin and verify the status of every deployed ScreenConnect server rather than assuming that an installation is unaffected based on age, configuration or deployment type.

How CVE-2026-84869 enables unauthorised execution

CVE-2026-84869 is described as an improper privilege management and missing authorisation vulnerability. It is mapped to CWE-269, Improper Privilege Management, and CWE-862, Missing Authorization.

In practical terms, an attacker can potentially transfer files to a device and execute them during an active ScreenConnect session without obtaining the required authorisation or confirmation from the host user. The attack therefore abuses functionality within a remote access session rather than relying on a user to approve each action.

A successful attacker could use that capability to introduce malicious payloads or unauthorised administration tools. Depending on the attacker’s access and objectives, subsequent activity could include creating persistence, accessing additional systems or establishing outbound communications from the affected host.

The active-session requirement is a significant detail. The reported vulnerability concerns the controls applied while a remote ScreenConnect session is already active. The source material does not establish that CVE-2026-84869 independently gives an unauthenticated attacker the ability to create a new session from the internet.

However, bypassing host authorisation for file transfer and execution can remove an important safety boundary within an existing session. It may also make harmful activity harder to distinguish from normal support work, particularly where administrators routinely use ScreenConnect to deploy files, run tools and troubleshoot endpoints.

Why managed environments face concentrated risk

Remote support platforms often connect administrators to numerous managed devices. If attackers successfully abuse the ScreenConnect vulnerability within that workflow, one compromised or improperly controlled access path could expose more than a single endpoint.

The risk is especially relevant to managed service environments because ScreenConnect may be used across multiple systems. The reported issue does not mean that every connected endpoint is automatically compromised, but each server, session and managed host should be considered when defining the scope of an investigation.

Internet exposure can increase opportunities for attackers to interact with a vulnerable service. CISA consequently advised organisations to assess the exposure of each asset and follow the risk-based update requirements in Binding Operational Directive 26-04.

Timeline of the ScreenConnect vulnerability warning

  • CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities Catalog on 11 September 2026.
  • The catalog entry confirmed that threat actors were actively exploiting the flaw in attacks.
  • CISA set a remediation deadline of 14 September 2026 for organisations covered by Binding Operational Directive 26-04.
  • The agency required forensic triage, indicating that patching alone was not considered sufficient.
  • By the report’s publication on 16 September 2026, no named attacker, confirmed ransomware use or detailed victim count had been disclosed.

ConnectWise has published a security bulletin addressing the issue and providing vendor guidance. CISA advised affected stakeholders to apply the relevant mitigations, assess internet exposure and discontinue use of the affected product if mitigations are unavailable.

How organisations should respond to CVE-2026-84869

Organisations running ScreenConnect should first use the ConnectWise bulletin to identify and apply the appropriate fix. They should validate coverage across every ScreenConnect server and associated managed environment, rather than treating one updated console as evidence that the entire deployment is protected.

External access should be restricted wherever operationally possible. Teams should also identify which instances were exposed to the internet and which hosts were reachable through active or historical ScreenConnect sessions during the relevant period.

Forensic triage should focus directly on activity that CVE-2026-84869 could enable. Relevant checks include:

  • Reviewing administrative accounts and recent account changes.
  • Examining active and historical remote sessions for unexpected access.
  • Checking file-transfer records for unfamiliar payloads or tools.
  • Investigating child processes launched through ScreenConnect.
  • Reviewing outbound connections from systems hosting the service.
  • Correlating suspicious activity across managed endpoints.

If evidence of compromise is found, credential resets and session-token invalidation may be appropriate as part of containment. Systems should also be examined for persistence or follow-on activity, because remediation of the ScreenConnect vulnerability will not remove files, accounts or access mechanisms already introduced by an attacker.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call