Active Exploitation Alert: ConnectWise ScreenConnect Improper Privilege Management / Missing Authorization (CVE-2026-84869) Added to CISA KEV — Unauthorized File Transfer and Execution via Active Remote Session

Active Exploitation Alert: ConnectWise ScreenConnect Improper Privilege Management / Missing Authorization (CVE-2026-84869) Added to CISA KEV — Unauthorized File Transfer and Execution via Active Remote Session

Executive Summary

CVE-2026-84869 is a critical improper-privilege-management and missing-authorization vulnerability in the ConnectWise ScreenConnect client. Per ConnectWise, a condition in the client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted. ConnectWise (CNA) rates the issue CVSS 3.1 9.9 Critical (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) under CWE-862 (Missing Authorization) and CWE-269 (Improper Privilege Management). Vendor bulletin severity is labeled Important with Priority 1 – High.

ConnectWise published the ScreenConnect 26.6.5 security bulletin on September 8, 2026. CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog on September 11, 2026, with a federal remediation due date of September 14, 2026, forensic triage required = Yes, and known ransomware campaign use = Unknown. NVD lists CPE matches for ScreenConnect up to (excluding) 26.6.5.9742. Cloud instances are upgraded by ConnectWise, but partners must still reinstall host clients and update access agents. On-premises deployments must upgrade to 26.6.5 (upgrade path requires 25.4 or later). Temporary mitigation: remove the TransferFiles role permission until patched.

Technical Information

Per ConnectWise, earlier versions of ScreenConnect Client Support and Access sessions had a client-side flaw in file-transfer handling: file-transfer and related execution actions could proceed during an active remote session without proper authorization or confirmation from the Host. Under certain circumstances this can enable files to be transferred to—and executed on—the Host client system, including elevated execution actions. The 26.6.5 patch strengthens client and session handling for file-transfer and file-execution actions. Servers are out of scope for this CVE.

Exact request/protocol details beyond the vendor summary are not published in the bulletin. Primary sources reviewed (ConnectWise bulletin, CISA KEV/alert, NVD) do not explicitly map CVE-2026-84869 to MITRE ATT&CK technique IDs. This advisory does not invent ATT&CK mappings or APT attribution.

Independent researchers (Huntress) have publicly described worm-like abuse patterns involving ScreenConnect sessions around the disclosure window; treat those reports as third-party context—do not treat secondary blog narrative as a substitute for ConnectWise remediation.

Affected Product Versions

Vendor: ConnectWise. Product: ScreenConnect (cloud and on-premises; client Support/Access sessions).

  • Affected: versions prior to 26.6.5 (NVD CPE up to excluding 26.6.5.9742).
  • Fixed: 26.6.5 (and later).
  • Servers: Not impacted.
  • Cloud: upgraded to 26.6.5; still reinstall host clients and update access agents.
  • On-premises: require 25.4+ to upgrade to 26.6.5; confirm eligibility on Administration > Overview.
  • Automate on-prem: 26.6.5 via Automate Product Updates when Assurance active.

Workaround and Mitigation

  1. Inventory every ScreenConnect instance (org + MSP), cloud and on-prem, including Automate-integrated.
  2. Upgrade to 26.6.5; reinstall host clients and update access agents.
  3. Temporary: deselect TransferFiles / TransferFilesInSession for all roles (Administration > Security > Roles).
  4. CISA forensic triage Yes / due 2026-09-14 — assess pre-patch compromise; do not close on server version alone.
  5. After patch: review users/roles, MFA, passwords; follow ConnectWise compromise checklist if needed.
  6. MSP attestation: build, client rebuild, TransferFiles posture, audit-log review for suspicious RunFiles/script activity.

Indicators of Compromise

Official vendor/CISA/NVD IoC packages: none as of 2026-09-21 (honest empty).

Third-party hunting leads (Huntress, attributed): ScreenConnect audit RunFiles/RanFiles of WSH/PowerShell from Process: Guest; rogue clients; anomalous wscript.exe from ScreenConnect.WindowsClient.exe. Do not invent ATT&CK IDs or extra IoCs.

References

Third-Party Risk Bridge: ScreenConnect as MSP / Remote-Access Control Plane

ConnectWise ScreenConnect is a core MSP and enterprise remote-access control plane. A client-side missing-authorization flaw enabling unauthorized file transfer and execution during an active session can turn a trusted RMM channel into cross-tenant payload delivery for every customer estate that trusts that MSP’s ScreenConnect stack. CISA KEV (added 2026-09-11, due 2026-09-14, forensic triage Yes) compresses the attestation window: confirm 26.6.5 server + rebuilt clients/agents, TransferFiles posture during any delay, and audit-log review before declaring clean.

Book a demo to see how Rescana tracks MSP/RMM and remote-access vendors for KEV-class ScreenConnect control-plane risk, version/agent attestation, and forensic-triage evidence.

Forward this advisory to your TPRM owner if an MSP or managed-service provider uses ScreenConnect (or Automate-integrated ScreenConnect) into your estate—they own the patch-per-instance, client rebuild, TransferFiles posture, and session-audit attestation asks above.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.