CVE-2026-84869 — ConnectWise ScreenConnect (versions below 26.6.5)
What ScreenConnect is: ConnectWise ScreenConnect is a remote support and access tool used by IT teams to connect to and manage computers remotely.
What it is: A missing authorisation flaw allows files to be transferred and executed through an active ScreenConnect session without the host's knowledge or approval.
Who's at risk: Anyone running ScreenConnect below version 26.6.5, particularly IT support teams and managed service providers. Active exploitation has been confirmed since August 20, per SecurityWeek.
CVSS: 9.9 — Critical. Patch today.
Root cause: The software fails to properly verify whether a user has permission before allowing file transfers and execution during a remote session. Think of it like a hotel key card that opens any room on the floor rather than just your own — the system trusts the session without checking what that session is actually allowed to do.
Attack vector: Attackers used social engineering (manipulating people into trusting something malicious) to trick victims into running modified ScreenConnect clients. Once installed, the rogue client checked for active sessions and pushed four VBScript payload files to connected machines, establishing persistence and spreading further — worm-like behaviour that jumps from machine to machine without further human interaction.
Detection strategies:
- Look for unexpected VBScript file creation or execution in system logs
- Audit active ScreenConnect sessions for connections you did not initiate
- Check for new scheduled tasks or startup entries added around August 20 onward
Recommended actions:
- Upgrade ScreenConnect to version 26.6.5 immediately
- As a temporary measure, disable the TransferFiles permission in ScreenConnect settings
- Review session logs for signs of unauthorised file transfers since August 20
ConnectWise ScreenConnect (versions below 26.6.5)
ConnectWise ScreenConnect is a remote support and access tool used by IT teams to connect to and manage computers remotely.
Sources

