ZeroDayAlert

CVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.

ConnectWise ScreenConnect Added to KEV 2026-09-11 Federal due 2026-09-14 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

ConnectWise ScreenConnect is a remote access and support tool widely deployed in IT service organisations, managed service providers, and corporate support teams. The vulnerability allows an attacker to perform file transfer and code execution through an active remote session without requiring authorisation from the user or host operator. The record does not specify which versions of ScreenConnect are vulnerable or whether cloud-hosted versus self-hosted deployments carry different risk.

How to check whether this touches you

  • Search your asset inventory and procurement records for ConnectWise ScreenConnect installations, including both on-premises deployments and any use of ConnectWise's cloud-hosted service.
  • Identify which ScreenConnect instances are reachable from the internet or from untrusted networks; these carry the highest risk of exploitation.
  • Note the current build number of each deployment by accessing the ScreenConnect console or agent properties; vendor patch announcements will specify affected build ranges, and version strings alone do not confirm whether a backported fix has been applied.
  • Review access logs to identify which remote sessions have been active and from which source addresses, as this will inform your retrospective investigation scope.

What to do

  1. Immediately obtain the vendor's official advisory and patch guidance from ConnectWise, including the specific build versions that address this vulnerability.
  2. Assess internet-facing ScreenConnect instances as your priority; if any are exposed without additional network controls, consider temporarily restricting access to known-good source addresses or requiring VPN transit.
  3. Apply the vendor's mitigations in accordance with CISA BOD 26-04 timelines; if your organisation is federal or operates critical infrastructure, the remediation due date is 14 September 2026.
  4. If patching cannot be completed within the required timeframe, evaluate whether discontinuing use of unpatched instances is feasible for your operational model.
  5. Enable and retain detailed logging of all file transfers and command execution events within ScreenConnect, and configure alerting for any transfer or execution activity that lacks corresponding user interaction records.
  6. Escalate to your security operations and incident response teams if you cannot patch or mitigate within the deadline, or if you discover evidence of unauthorised file transfer or execution during active sessions.

If you find you were exposed

Exploitation typically precedes public disclosure by weeks or months, so hunt backwards from the disclosure date using your session logs, file transfer records, and endpoint execution histories. Cross-reference any remote sessions that lack explicit user authorisation with corresponding file system and process creation events on the affected hosts. Log retention policies are your constraint; if you retain fewer than 90 days of ScreenConnect session data, you may be unable to confirm retrospective compromise.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-84869 is being exploited. It cannot tell you whether ScreenConnect is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →