CISA Adds ConnectWise ScreenConnect Vulnerability to Exploited List
CISA has recorded active exploitation of CVE-2026-84869 in ConnectWise ScreenConnect. A fix is available in version 26.6.5.

A vulnerability in ConnectWise ScreenConnect identified as CVE-2026-84869 has been added to the U.S. Known Exploited Vulnerabilities (KEV) catalog. On September 11, 2026, CISA designated it as actively exploited in real-world environments. The vulnerability affects versions of the ScreenConnect remote access tool older than 26.6.5.
ConnectWise released a security fix on September 8 in ScreenConnect version 26.6.5. According to the company’s notice, the vendor automatically updated cloud instances. Administrators of locally operated, or on-premise, installations must perform the update themselves.
The ConnectWise ScreenConnect vulnerability affects active sessions
According to the ConnectWise security bulletin, the vulnerability may under certain circumstances allow unauthorized file transfer and execution through an active remote session without host confirmation. The vendor states that the ScreenConnect server itself is not directly affected.
ScreenConnect is used for remote access and device management. The ability to transfer and execute a file in a remote session without user confirmation therefore poses a risk to the remote endpoint accessible through the session.
Inclusion in KEV means that CISA has recorded exploitation of the specific vulnerability in real-world environments. For federal agencies, it set a remediation deadline of September 14, 2026. The KEV catalog also recommends following the vendor’s instructions.
Fix 26.6.5 and temporary restriction of permissions
The priority for organizations with their own ScreenConnect installation is to verify the version in use and update to 26.6.5 or later. According to available information, the risk primarily concerns unpatched on-premise environments and active sessions.
If an immediate update is not possible, ConnectWise lists a temporary mitigation. Administrators should remove the TransferFiles permission from all roles, or, in older configurations, the TransferFilesInSession permission. This measure is intended for the period until the fix is deployed.
- verify whether the on-premise server is running ScreenConnect 26.6.5 or later;
- check roles and permissions for file transfers;
- if the fix cannot be deployed immediately, remove TransferFiles or TransferFilesInSession from all roles;
- after updating, review accounts, roles, and audit logs according to ConnectWise instructions.
Details of the current exploitation are still unavailable
CISA and ConnectWise have not publicly disclosed who is exploiting the vulnerability, at what scale, against which organizations, or which technical indicators administrators could use to check for compromise. It has also not been publicly confirmed that CVE-2026-84869 is part of ransomware campaigns; CISA marks this connection as unknown.
Administrators should monitor for any additional indicators of compromise or exploitation details from CISA and ConnectWise. Until then, the practical step is to deploy the available version 26.6.5 or restrict file-transfer permissions wherever the update has not yet been applied.
Sources
- CISA Known Exploited Vulnerabilities Catalog – Confirms the addition of CVE-2026-84869 to KEV on September 11, 2026, recorded exploitation, the September 14, 2026 remediation deadline, and the requirement to follow the vendor’s instructions.
- ConnectWise ScreenConnect 26.6.5 Security Patch – Confirms the affected versions, the nature of the client vulnerability, release of fix 26.6.5, automatic cloud updates, and temporary mitigation for on-premise deployments.
- ConnectWise CVE Advisory Repository – Confirms that ConnectWise lists CVE-2026-84869 as a publicly disclosed ScreenConnect security fix from September 8, 2026.
Verified and updated: 09/12/2026 06:23



