What Changed
ConnectWise released ScreenConnect 26.6.5 on September 8, 2026 to fix CVE-2026-84869, a CVSS 9.9 missing-authorization / improper privilege-management flaw in the ScreenConnect client (servers are not impacted). Under certain circumstances, files can be transferred and executed through an active remote session without authorization or Host confirmation — including elevated execution actions.
Affected: client versions prior to 26.6.5. Cloud instances were updated by ConnectWise; partners still need to reinstall host clients and update access agents. On-premises partners must upgrade to 26.6.5 (requires 25.4 or later as the upgrade floor) and then refresh clients/agents.
Huntress documented incidents where modified ScreenConnect clients propagated VBScript payloads (1.vbs–4.vbs) to newly connected endpoints in a worm-like pattern. Huntress’s John Hammond told Help Net Security that the observed activity aligns with CVE-2026-84869. CISA added the CVE to KEV on September 11, 2026, with a federal due date of September 14, 2026.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Temporary mitigation if you cannot patch immediately: deselect TransferFiles (legacy: TransferFilesInSession) for all roles under Administration → Security → Roles.
Why This Matters Operationally
ScreenConnect sits in the trust path for MSPs and internal IT. A low-privilege session that can push and run files on the host without confirmation turns remote support into remote compromise — and Huntress’s cases show how quickly that becomes lateral movement across every newly connected machine.
What Defenders Should Verify First
- Confirm ScreenConnect server/cloud is on 26.6.5+, then reinstall host clients and update access agents fleet-wide.
- Build a session group for
GuestClientVersion < 26.6.5and drive reinstalls until it empties. - If patching slips, remove TransferFiles from every role now.
- Hunt audit logs for RunFiles / RanFiles tied to guest processes; reimage confirmed compromises from known-good media.
- Scrutinize on-premises installations especially (Huntress guidance).
Source Context
- ConnectWise: 2026-09-08 ScreenConnect Bulletin (26.6.5 / CVE-2026-84869)
- Help Net Security: ScreenConnect file-transfer flaw / Huntress incidents
- CISA: Adds Three KEVs including ScreenConnect
- The Hacker News: CISA adds ScreenConnect (due Sep 14)
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.