ConnectWise ScreenConnect CVE-2026-84869: Guest Session, Host Compromise — KEV Due Today

By George Bailey   Published: 09/13/26   Updated: 09/13/26   2 min read

What Changed

ConnectWise released ScreenConnect 26.6.5 on September 8, 2026 to fix CVE-2026-84869, a CVSS 9.9 missing-authorization / improper privilege-management flaw in the ScreenConnect client (servers are not impacted). Under certain circumstances, files can be transferred and executed through an active remote session without authorization or Host confirmation — including elevated execution actions.

Affected: client versions prior to 26.6.5. Cloud instances were updated by ConnectWise; partners still need to reinstall host clients and update access agents. On-premises partners must upgrade to 26.6.5 (requires 25.4 or later as the upgrade floor) and then refresh clients/agents.

Huntress documented incidents where modified ScreenConnect clients propagated VBScript payloads (1.vbs4.vbs) to newly connected endpoints in a worm-like pattern. Huntress’s John Hammond told Help Net Security that the observed activity aligns with CVE-2026-84869. CISA added the CVE to KEV on September 11, 2026, with a federal due date of September 14, 2026.

Temporary mitigation if you cannot patch immediately: deselect TransferFiles (legacy: TransferFilesInSession) for all roles under Administration → Security → Roles.

Why This Matters Operationally

ScreenConnect sits in the trust path for MSPs and internal IT. A low-privilege session that can push and run files on the host without confirmation turns remote support into remote compromise — and Huntress’s cases show how quickly that becomes lateral movement across every newly connected machine.

What Defenders Should Verify First

Source Context

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.