Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Font size: +
9 minutes reading time (1819 words)

Cybersecurity Threat Advisory: ScreenConnect Security Alert: What Businesses Need to Know About CVE-2026-84869

Threat update

A newly disclosed security issue affecting ConnectWise ScreenConnect could allow files to be transferred and executed during an active remote-support session without the authorization or confirmation normally expected in certain circumstances. ConnectWise has released ScreenConnect 26.6.5 to address the vulnerability, identified as CVE-2026-84869, and recommends affected organizations update as soon as possible.  

Remote-support software is incredibly useful.

It lets an IT technician help an employee without driving across town, troubleshoot a computer from another office, install approved software, transfer a needed file, or solve a problem while the person continues working.

But there's another side to that convenience.

Remote-support software is powerful because it is trusted to do things ordinary applications can't.

When a security problem affects that trust, businesses need to pay attention.

That's exactly why the latest ScreenConnect security update matters.

Technical Detail and Additional Info

What happened with ScreenConnect?

 ConnectWise identified a security condition involving file transfers and file execution within active ScreenConnect remote sessions. Under certain circumstances, files could be transferred and executed without the expected authorization or confirmation from the host.

ConnectWise initially published an advisory on September 3 while it worked on remediation.

The permanent security update is now available.

On September 8, ConnectWise published its security bulletin for CVE-2026-84869 and released ScreenConnect 26.6.5 to address the problem.

ConnectWise has assigned the vulnerability a CVSS base score of 9.9 out of 10 and classifies the update as Priority 1 – High.

That's not something an organization using an affected version should put on next month's to-do list.

What is ScreenConnect?

ScreenConnect is remote-access and remote-support software used by IT professionals, internal technology teams, and managed service providers.

Imagine an employee calls the help desk because an application won't open.

Rather than sending someone physically to that desk, an authorized technician can establish a remote session, see the computer, troubleshoot the issue, transfer approved files, and make necessary changes.

That's convenient for the employee and much more efficient for IT.

But consider what those capabilities mean from a security perspective.

Remote-access tools can have considerable control over the computers they manage.

A weakness involving what files can be transferred or executed through one of those sessions deserves a very different level of attention than a minor cosmetic software bug. 

What is CVE-2026-84869?

CVE-2026-84869 is the identifier assigned to the ScreenConnect vulnerability involving missing authorization and improper privilege management.

In plain English, the issue could allow files to be transferred and executed through an active remote session without proper authorization or host confirmation under certain conditions.

ConnectWise lists two relevant weakness categories:

Missing Authorization

Improper Privilege Management

The vulnerability carries a 9.9 CVSS score.

CVSS is a standard method security professionals use to describe the severity of software vulnerabilities. The scale runs from 0 to 10.

A score of 9.9 tells you this deserves attention.

It does not, by itself, mean every ScreenConnect system has been hacked.

That's an important distinction.

Which ScreenConnect versions are affected?

ScreenConnect versions earlier than 26.6.5 are affected by this issue. Version 26.6.5 contains the security remediation.

Here's the simplest way to look at it:

Environment

Current action

ScreenConnect earlier than 26.6.5

Update required

ScreenConnect 26.6.5 or later

Security remediation included

Cloud ScreenConnect

Cloud instances are upgraded automatically

On-premises ScreenConnect

Administrator should upgrade to 26.6.5

Host clients/access agents

Reinstall/update after the server or cloud upgrade

ScreenConnect server itself

Not impacted by this specific vulnerability

For on-premises installations, ConnectWise recommends checking that the organization's license is eligible for version 26.6.5 before beginning the upgrade.

Why does a file-transfer vulnerability matter? 

File transfer sounds harmless until you consider what a remote-management system can do with the file after it arrives.

IT technicians legitimately transfer files all the time.

It might be a diagnostic utility.

A software installer.

A configuration file.

A script.

A log.

That's normal administration.

The concern is what happens if that same mechanism can be abused to move and execute something the organization didn't authorize.

A malicious file doesn't need to announce itself as malware.

It could appear to be an ordinary utility or installer.

The larger security lesson goes beyond ScreenConnect:

Any tool capable of remotely administering computers should be treated as a high-trust application.

Permissions should be limited. Accounts should be protected. Updates should be installed quickly. Activity should be monitored.

Does this affect cloud and on-premises ScreenConnect differently? 

The vulnerability affects ScreenConnect clients associated with both cloud and on-premises environments, but the remediation process differs.

For ScreenConnect Cloud, ConnectWise says cloud instances are upgraded automatically.

After the upgrade, organizations should make sure host clients are reinstalled and access agents updated.

For on-premises ScreenConnect, administrators need to upgrade to version 26.6.5.

If an organization can't apply the update immediately because of a maintenance window or change freeze, ConnectWise has also provided a temporary mitigation.

But temporary is the important word.

What can organizations do if they cannot patch immediately? 

ConnectWise recommends temporarily disabling file-transfer permission for applicable user roles if the 26.6.5 update cannot be installed immediately.

Within ScreenConnect, administrators can review:

Administration → Security → Roles

Then review the relevant session groups and deselect the TransferFiles permission where it is enabled.

ConnectWise notes that this permission was previously called TransferFilesInSession.

That change should be repeated across applicable roles.

This reduces exposure, but ConnectWise is clear that it is not a substitute for installing the security update.

The better long-term action is still to move to the patched version. 

What should businesses ask their IT provider? 

If another company manages ScreenConnect for your organization, you don't need to become a ScreenConnect administrator yourself.

You do need confirmation that the issue has been addressed.

Ask:

1. Do we use ConnectWise ScreenConnect?

2. Are our ScreenConnect clients running version 26.6.5 or later?

3. If we're cloud-hosted, have the host clients and access agents been updated?

4. If we're on premises, has the 26.6.5 security update been installed?

5. Have user accounts, permissions, and administrative access been reviewed?

6. Has multifactor authentication been enabled for appropriate accounts?

7. Have recent remote sessions and audit logs been reviewed for unusual activity?

Those are reasonable questions.

A good technology provider should be able to answer them.

What should you do after installing the patch? 

Patching closes the known vulnerability, but ConnectWise also recommends reviewing the security of the ScreenConnect environment afterward.

That includes looking at users who have access to ScreenConnect.

Are all the accounts recognizable?

Do those users still need the permissions they have?

Are any old technician or administrator accounts hanging around?

ConnectWise recommends reviewing users and roles, removing unrecognized accounts, changing passwords where appropriate, enabling MFA, and reviewing audit information.

This is a useful habit even when there isn't a security bulletin.

Old accounts and excessive permissions have a way of accumulating over time.

Security maintenance isn't only about installing software updates.

It's also about periodically asking:

"Who has access to this, and do they still need it?"

What if you think ScreenConnect may have been compromised? 

 Don't simply patch the software and assume the problem is solved if you have evidence suggesting an actual compromise.

ConnectWise recommends following your organization's established incident-response process.

That can include isolating affected systems, preserving information for analysis, reviewing audit logs, forcing technicians to sign in again, changing credentials, and investigating whether activity extended beyond ScreenConnect.

This is where the difference between vulnerability management and incident response becomes important.

A vulnerability means a weakness exists.

An incident means there is reason to believe someone may have used that weakness—or another route—to gain unauthorized access.

Those situations require different responses.

Why should businesses care about remote-access security? 

Most employees will never log into the administrative side of ScreenConnect.

That doesn't mean the platform is irrelevant to them.

Remote-management technology often sits quietly behind the scenes keeping computers working.

And that's precisely why protecting it matters.

Think of your office building.

Most employees don't manage the master-key system either. But everyone has an interest in making sure those keys don't end up in the wrong hands.

Remote-access platforms deserve the same mindset.

Keep them updated.

Limit permissions.

Protect administrative accounts.

Use MFA.

Monitor activity.

Remove access that is no longer needed.

And when a vendor publishes a high-priority security update, don't assume someone else took care of it.

Verify.

What should ScreenConnect users do now? 

The immediate action is straightforward:

Confirm that your ScreenConnect environment has been remediated for CVE-2026-84869.

For affected on-premises environments, that means upgrading to ScreenConnect 26.6.5 or later and then updating the applicable clients and agents.

Cloud customers receive the platform update automatically but should still ensure the appropriate host clients and access agents are updated.

If immediate patching isn't possible, use ConnectWise's temporary file-transfer mitigation until the security update can be applied.

And if you see evidence of suspicious activity, don't treat it as an ordinary patching exercise.

Escalate it as a potential security incident.

Cybersecurity isn't about panicking every time a vulnerability makes the news.

It's about recognizing which issues matter, understanding your exposure, and taking the appropriate action while there is still time to do so. 

Frequently Asked Questions

Cybersecurity Threat Advisory: AI-Powered Server A...

Related Posts

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024