ConnectWise Patches Critical ScreenConnect Flaw Exploited in Attacks
Share
ConnectWise has released urgent security patches for a critical vulnerability in its ScreenConnect remote access and support software, which is currently being exploited in worm-like attacks.
The flaw, identified as CVE-2026-84869, has been assigned a CVSS score of 9.9 out of 10. It is classified as a missing authorisation and improper privilege management issue.
The security defect creates a condition where attackers can transfer and execute files through an active remote session without the host’s confirmation or authorisation. This allows for unauthorised command execution and file manipulation during ongoing support sessions.
Worm-like Propagation Observed in the Wild
Cybersecurity firm Huntress reported that exploitation of the vulnerability has been occurring since 20 August 2026. In observed incidents, attackers used social engineering to trick targets into executing rogue ScreenConnect clients.
Once running, these modified clients scan for active remote sessions to push VBScript payloads. These payloads are designed to establish persistence on the target system and attempt to propagate to other ScreenConnect clients across the network, mirroring worm-like behaviour.
Remediation and Mitigation
ConnectWise has resolved the issue in ScreenConnect version 26.6.5 and has urged all users to apply the update immediately. The patch includes updates designed to strengthen session handling for file-transfer and file-execution actions.
As a temporary mitigation, the vendor recommends disabling the TransferFiles permission within the ScreenConnect settings to prevent unauthorised file movements while waiting to patch.
CISA Mandates Patching for Federal Agencies
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-84869 to its Known Exploited Vulnerabilities (KEV) catalogue. Under current federal mandates, US government agencies are required to remediate this vulnerability within three days of its addition to the list.




Leave a Reply