Download Privacy Needle App

Type to search

Cybersecurity

ConnectWise Patches Critical ScreenConnect Flaw Exploited in Attacks

Share

ConnectWise has released urgent security patches for a critical vulnerability in its ScreenConnect remote access and support software, which is currently being exploited in worm-like attacks.

The flaw, identified as CVE-2026-84869, has been assigned a CVSS score of 9.9 out of 10. It is classified as a missing authorisation and improper privilege management issue.

The security defect creates a condition where attackers can transfer and execute files through an active remote session without the host’s confirmation or authorisation. This allows for unauthorised command execution and file manipulation during ongoing support sessions.

Worm-like Propagation Observed in the Wild

Cybersecurity firm Huntress reported that exploitation of the vulnerability has been occurring since 20 August 2026. In observed incidents, attackers used social engineering to trick targets into executing rogue ScreenConnect clients.

Once running, these modified clients scan for active remote sessions to push VBScript payloads. These payloads are designed to establish persistence on the target system and attempt to propagate to other ScreenConnect clients across the network, mirroring worm-like behaviour.

Remediation and Mitigation

ConnectWise has resolved the issue in ScreenConnect version 26.6.5 and has urged all users to apply the update immediately. The patch includes updates designed to strengthen session handling for file-transfer and file-execution actions.

As a temporary mitigation, the vendor recommends disabling the TransferFiles permission within the ScreenConnect settings to prevent unauthorised file movements while waiting to patch.

CISA Mandates Patching for Federal Agencies

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-84869 to its Known Exploited Vulnerabilities (KEV) catalogue. Under current federal mandates, US government agencies are required to remediate this vulnerability within three days of its addition to the list.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.