CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are actively exploiting a critical vulnerability in ConnectWise ScreenConnect.
ConnectWise released a temporary mitigation for the missing-authentication flaw on September 7, advising security teams to disable the TransferFiles permission to help block potential attacks.
ScreenConnect vulnerability allows file transfers and execution
The vulnerability, tracked as CVE-2026-84869, affects the ScreenConnect client. ConnectWise has patched the flaw in ScreenConnect version 26.6.5 and later.
The vulnerability could allow an attacker with basic privileges to transfer or execute files through a low-complexity attack that does not require user interaction.
According to CISA, the flaw involves improper privilege management and missing authentication. An attacker could transfer or execute files through an active remote session without authentication or host verification.
“These types of vulnerabilities are a frequent attack vector for malicious cyber attackers and pose significant risks to federal enterprises,” CISA said.
CISA adds CVE-2026-84869 to its exploited vulnerabilities catalog
CISA added CVE-2026-84869 to its Known Exploited Vulnerabilities Catalog on Friday. The agency ordered U.S. federal agencies to protect their systems from the ongoing attacks within three days.
Since 2024, CISA has listed four ScreenConnect security issues as actively exploited. Two of those vulnerabilities have also been used in ransomware attacks.
More than 1,000 unpatched ScreenConnect instances exposed
Internet threat monitoring organization Shadowserver is tracking more than 1,000 ScreenConnect instances that have not yet been patched and remain exposed to online attacks.
Most of the vulnerable instances are located in North America, with 758 identified systems, followed by Europe with 180.

ScreenConnect remains a frequent target
ScreenConnect vulnerabilities are frequently targeted by financially motivated and state-sponsored hacking groups.
For example, the North Korean-backed Kimsuky hacking group and several ransomware gangs exploited another ScreenConnect vulnerability, CVE-2024-1709, in 2024.
Last year, ConnectWise also revoked a digital code-signing certificate after revealing that suspected state-sponsored hackers had infiltrated a limited number of customer systems through code-injection attacks involving a ViewState flaw, CVE-2025-3935, in cloud-based instances.
Most recently, ConnectWise addressed a cryptographic signature verification vulnerability, CVE-2026-3564, in March. The flaw could allow an attacker to hijack an unpatched ScreenConnect server.
Why ScreenConnect users should act
ConnectWise serves more than 100,000 IT providers worldwide. Managed service providers (MSPs) and IT teams widely use ScreenConnect for troubleshooting, patching, and system maintenance.
Organizations using ScreenConnect should apply the available update and follow ConnectWise’s temporary mitigation guidance by disabling the TransferFiles permission while investigating potentially exposed systems.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



