A remote-support tool used by thousands of IT departments and managed service providers just became CISA’s latest three-day fire drill. On September 11, 2026, the agency added CVE-2026-84869, a critical flaw in ConnectWise ScreenConnect, to its Known Exploited Vulnerabilities catalog, confirming attackers were already using it in live attacks. The bug carries a CVSS score of 9.9 out of 10, and federal civilian agencies had until September 14, 2026, three days later, to patch it or rip the software out.
The flaw lets an attacker transfer and run files through an already-open ScreenConnect remote session without the host ever clicking “allow.” Security researchers have described the exploitation pattern as worm-like, spreading from one connected endpoint to the next without needing a fresh phishing email or stolen password each time. For an industry still recovering from ScreenConnect’s catastrophic 2024 breach, the timing could hardly be worse.
What Happened: A Critical Flaw Lands in the Tool MSPs Trust Most
ConnectWise published a security bulletin on September 8, 2026, disclosing a missing-authorization and improper-privilege-management issue in the ScreenConnect client. Three days later, CISA confirmed active exploitation and added the bug to its Known Exploited Vulnerabilities (KEV) catalog, the federal government’s running list of flaws attackers are using right now rather than flaws that merely could be dangerous someday.
ScreenConnect is remote-support and remote-monitoring software, the kind of tool an IT help desk uses to take control of your laptop and fix a problem without sending a technician to your desk. It’s a staple at managed service providers, which lean on it to service dozens or hundreds of client networks from a single console. That concentration of access is exactly what makes a flaw like CVE-2026-84869 so consequential: compromise one ScreenConnect instance, and an attacker potentially inherits a direct line into every machine it manages.
Inside CVE-2026-84869: What the Flaw Actually Does
The CVSS 3.1 vector for CVE-2026-84869 is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, which translates to a network-exploitable bug requiring low attacker privilege, no user interaction, and a changed scope with full impact on confidentiality, integrity, and availability. In plain terms, it’s about as bad as a vulnerability gets without reaching a perfect 10.0.
According to the National Vulnerability Database, the condition allows files to be “transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances.” Normally, ScreenConnect requires the person on the receiving end to approve a session or a file transfer. This flaw lets that step get skipped, turning a support session that a technician (or an attacker posing as one) already has open into a channel for silently dropping and running arbitrary code.
Why Skipping Host Confirmation Matters
Remote-access tools build trust into their design specifically so a user can see and approve what’s happening on their own machine. Removing that checkpoint doesn’t just make the software more convenient for attackers, it also makes detection harder. A file transfer that never triggers a confirmation prompt is a file transfer that never shows up in the mental model of the person sitting at the keyboard, which is often the last line of defense before a security team notices anything is wrong.
Timeline: From Patch Tuesday to a Federal Deadline
The sequence moved fast, even by 2026 standards. ConnectWise’s own bulletin and the CVE record both list September 8, 2026, as the disclosure date, with ScreenConnect 26.6.5 shipping as the fix. CISA’s KEV listing followed on September 11, and the compliance clock for federal agencies closed just three days later, on September 14. That compressed window puts CVE-2026-84869 in the same tier of urgency as the Arista zero-day shattered.io covered recently, which also carried a three-day CISA remediation deadline.
For organizations outside the federal government, the KEV deadline isn’t legally binding, but it functions as an informal industry clock. Security teams routinely treat KEV additions as a signal to prioritize patching regardless of sector, and cyber insurers increasingly ask about KEV compliance during renewal reviews.
What “Worm-Like Attacks” Actually Means Here
Security researchers covering the exploitation described the activity as worm-like, a term that implies self-propagation from one compromised endpoint to adjacent ones without fresh manual effort from the attacker each time. In the context of ScreenConnect, that likely means an attacker who gains access to one managed session can use the unauthorized file transfer and execution path to push tooling onto connected hosts in sequence, rather than needing to individually phish or brute-force each target.
No Named Threat Actor, Yet
Unlike some KEV additions that arrive with a ransomware gang’s name already attached, CVE-2026-84869’s public reporting has not identified a specific group or APT behind the exploitation. CISA’s own tracking reportedly lists known ransomware campaign use as “unknown” for this entry so far. That could change quickly, as it did with the 2024 ScreenConnect flaw discussed below, where attribution emerged only after incident responders worked through a wave of intrusions.
ConnectWise’s Patch, and What Admins Still Have to Do Manually
ConnectWise’s advisory points administrators to ScreenConnect 26.6.5 or later. The company stated that the 26.6.5 patch “includes updates to strengthen client and session handling for file-transfer and file-execution actions.” On-premises customers running versions older than 25.4 reportedly need an intermediate upgrade step before they can move directly to 26.6.5, which is the kind of detail that trips up organizations trying to patch quickly under deadline pressure.
Patching the Server Isn’t the Whole Job
Updating the central ScreenConnect server doesn’t automatically protect every endpoint it manages. Guidance tied to the advisory notes that client installations and active hosts that weren’t updated or reinstalled in line with ConnectWise’s instructions may still carry the vulnerable behavior. That distinction matters enormously for MSPs managing thousands of individual client machines, where a server-side patch can create a false sense of completion while stale clients remain exposed.
CISA’s Known Exploited Vulnerabilities Catalog, Explained
The KEV catalog exists because CVSS scores alone don’t tell security teams what to fix first. A 9.9-rated bug sitting unused on a shelf is a lower operational priority than a 7.5-rated bug being actively weaponized against real networks. CISA’s catalog solves that by listing only vulnerabilities with confirmed, real-world exploitation, paired with a remediation deadline for federal civilian executive branch agencies under Binding Operational Directive 22-01.
CVE-2026-84869 is one of a long run of KEV additions shattered.io has tracked this year. Recent entries include a pair of Citrix NetScaler zero-days rated CVSS 9.5, a TeamCity flaw that ransomware actors used against roughly 160 servers, a F5 BIG-IP zero-day scoring 9.8, and a maximum-severity Cisco ISE bug with no available workaround.
Déjà Vu: ScreenConnect’s 2024 Brush With Disaster
This isn’t ScreenConnect’s first appearance on the KEV list. In February 2024, ConnectWise disclosed CVE-2024-1709, an authentication-bypass flaw affecting on-premises versions 23.9.7 and earlier, which earned a perfect CVSS score of 10.0. CISA added it to the KEV catalog on February 22, 2024, with a federal deadline of February 29, giving agencies just a week to respond. The catalog flagged the bug with known ransomware use, and researchers at Wiz identified more than 8,800 internet-exposed ScreenConnect servers that were potentially vulnerable at the time.
That 2024 incident became a reference case for how quickly a single remote-access flaw can cascade through the MSP ecosystem, since compromising one ScreenConnect server can expose every downstream client it touches. CVE-2026-84869 doesn’t appear to be as catastrophic in scale yet (no confirmed server count or named victim has surfaced in public reporting as of this writing) but the pattern, a critical authorization flaw in the same product line, two and a half years later, is drawing direct comparisons from security researchers.
CVE-2026-84869 at a Glance
| Detail | Information |
|---|---|
| CVE ID | CVE-2026-84869 |
| CVSS 3.1 score | 9.9 (Critical) |
| CVSS vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| Vulnerability type | Missing authorization / improper privilege management |
| Affected product | ConnectWise ScreenConnect (client) |
| Affected versions | All versions prior to 26.6.5 |
| Fixed version | 26.6.5 (build 26.6.5.9742 or later, per some trackers) |
| Bulletin published | September 8, 2026 |
| Added to CISA KEV | September 11, 2026 |
| Federal remediation deadline | September 14, 2026 |
| Exploitation status | Actively exploited in the wild; described as worm-like |
How This Compares: A Year of Critical Remote-Access and Collaboration Flaws
Put next to the rest of 2026’s KEV additions, ScreenConnect’s bug sits near the top of the severity range but is not the year’s single worst entry. It also joins a growing pattern: enterprise software that’s supposed to make IT management easier is increasingly the first thing attackers go after.
| Product | CVE | CVSS | CISA Deadline Window |
|---|---|---|---|
| ConnectWise ScreenConnect | CVE-2026-84869 | 9.9 | 3 days |
| Arista (VeloCloud) | Not yet assigned per reporting | 10.0 | 3 days |
| Cisco ISE | CVE-2026-76460 | 10.0 | No workaround available |
| TeamCity | CVE-2026-63077 | 9.8 | Ransomware hit ~160 servers |
| F5 BIG-IP | CVE-2026-94127 | 9.8 | Zero-day, patched |
| Citrix NetScaler | Multiple, unpatched disclosures | 9.5 | Deadline missed by some orgs |
| Microsoft SharePoint (on-prem) | CVE-2026-65660 | 8.8 | Added to KEV |
Six critical-to-maximum-severity flaws in widely deployed enterprise infrastructure, all surfacing within roughly the same two-month window, is not a coincidence security teams can write off as noise. It reflects where attackers are concentrating effort: software that sits at the center of IT operations, carries broad administrative reach, and is often harder to take offline for patching than a single application server.
Why RMM Tools Are Now a Favorite Attack Vector
Remote monitoring and management (RMM) software has become one of the most efficient paths into a network precisely because it’s designed to look legitimate. A ScreenConnect session, a SimpleHelp connection, or any similar tool running on an endpoint doesn’t trip the same alarms that a brand-new unauthorized remote-access binary would. Security teams expect to see it there.
Acronis’s Cyberthreats Report covering the second half of 2025 found that exploitation of unpatched software was the dominant initial-access vector in the MSP and supply-chain ransomware incidents it analyzed, and that supply-chain and third-party compromises affected at least 1,200 publicly identified victims between January and November 2025. The same report detailed a DragonForce ransomware incident in which attackers compromised an MSP, pivoted through its SimpleHelp RMM deployment, and moved into downstream customer environments before deploying ransomware and stealing data. ConnectWise’s own 2026 Managed Service Provider Threat Report, drawing on 2025 activity, reportedly found that attackers are relying less on brand-new software exploits and more on abusing identity, remote-access tools, and software supply chains inside MSP-managed environments.
The MSP Supply-Chain Problem: One Login, Many Victims
The math that makes RMM compromise so attractive is simple: breach one MSP, and you potentially inherit administrative access to every one of its clients. Security firm Dragos reported that, in its Q1 2026 industrial ransomware analysis, the Medusa ransomware group used RMM tooling for lateral movement after gaining initial access, alongside credential theft, a pattern increasingly common across ransomware operations regardless of target sector.
Market and Cyber-Insurance Fallout
For MSPs and the vendors that supply them, incidents like CVE-2026-84869 carry a reputational cost that compounds with each KEV listing. Cyber insurance underwriters have grown more attentive to patch cadence and KEV compliance when assessing renewal risk, and an MSP that can’t demonstrate rapid remediation on a tool as central as its remote-support platform may face higher premiums or narrower coverage. ConnectWise, for its part, has continued shipping patches on a predictable disclosure-to-fix timeline, which security researchers generally treat as a mitigating factor even when the underlying bug is severe.
What Security Teams Should Do This Week
Organizations running ScreenConnect, whether as a standalone IT tool or as the backbone of an MSP’s service delivery, should treat this as an immediate action item rather than a routine patch-cycle entry. The practical checklist looks like this:
- Confirm the ScreenConnect server is running version 26.6.5 or later, not just scheduled for an update.
- Verify that on-premises deployments below version 25.4 complete the required intermediate upgrade step before jumping to 26.6.5.
- Audit individual client installations and active hosts, since a patched server does not automatically remediate outdated clients.
- Review session logs for unexplained file transfers or executions that didn’t generate a host confirmation prompt.
- If ScreenConnect manages third-party client networks, notify those clients directly rather than assuming the patch alone covers them.
A general, illustrative way administrators check the installed version on a Windows host before confirming an upgrade:
# Illustrative example: check installed ScreenConnect version on a Windows host
Get-ItemProperty "HKLM:\SOFTWARE\ScreenConnect*" | Select-Object DisplayVersion, DisplayName
Teams that manage ScreenConnect at scale should also revisit broader remote-access hygiene, including multi-factor authentication on the administrative console and network segmentation that limits what a compromised session can actually reach, lessons that organizations recovering from the Kiteworks shutdown-and-patch episode earlier this year learned the hard way.
Predictions: Where This Goes Next
Based on the pattern of 2026’s KEV additions and the current reporting on CVE-2026-84869, a few outcomes look likely over the coming weeks and months:
- Attribution will emerge. Given how the 2024 ScreenConnect flaw eventually produced named ransomware activity, expect incident responders to connect CVE-2026-84869 to at least one identifiable group within the next few months.
- CISA deadlines keep shrinking. The three-day windows given to both the Arista zero-day and CVE-2026-84869 suggest CISA is shortening its remediation clock for flaws in administrative-access software specifically.
- More RMM vendors land on the KEV list. As attackers shift toward abusing trusted remote-access channels rather than hunting novel exploits, expect additional RMM and remote-support products to surface in KEV entries before year’s end.
- MSPs face tighter insurance scrutiny. Expect cyber insurers to add more specific RMM-patch-cadence questions to renewal questionnaires, following the broader trend of tying premiums to demonstrated KEV responsiveness.
- Zero-trust session controls gain traction. Expect more MSPs to adopt stricter confirmation and segmentation requirements on remote-support sessions, treating “no user interaction required” vulnerabilities as a design risk rather than an edge case.
These are informed projections based on current trends, not confirmed outcomes, and should be read as analysis rather than fact.
Frequently Asked Questions
What is CVE-2026-84869?
It’s a critical missing-authorization vulnerability in ConnectWise ScreenConnect, rated CVSS 9.9, that lets an attacker transfer and execute files through an active remote session without the host’s authorization or confirmation.
Which ScreenConnect versions are affected?
All versions prior to 26.6.5 are affected, according to ConnectWise’s advisory and the NVD entry. On-premises deployments below version 25.4 reportedly need an intermediate upgrade before moving to 26.6.5.
Is CVE-2026-84869 being actively exploited right now?
Yes. CISA added it to the Known Exploited Vulnerabilities catalog on September 11, 2026, confirming real-world exploitation, and security researchers have described the activity as worm-like.
Has a specific ransomware group or APT been tied to this flaw?
Not publicly, as of this writing. CISA-related tracking has reportedly listed known ransomware campaign use as “unknown” for this entry, unlike the 2024 ScreenConnect flaw, which was explicitly flagged for ransomware use.
What should ScreenConnect administrators do right now?
Upgrade to ScreenConnect 26.6.5 or later immediately, verify all individual client installations and active hosts were updated or reinstalled as instructed, and review session logs for unauthorized file transfers or executions.
Is this the same vulnerability as the 2024 ScreenConnect incident?
No. The 2024 flaw, CVE-2024-1709, was a separate authentication-bypass bug rated CVSS 10.0 that was tied to confirmed ransomware use. CVE-2026-84869 is a distinct, newly disclosed flaw in the same product line.
Are managed service providers at greater risk from this flaw than typical businesses?
Generally yes, because MSPs often run ScreenConnect as the central tool managing dozens or hundreds of client networks. A single compromised MSP instance can expose every downstream organization it services, a pattern documented in other RMM-based supply-chain incidents.
Does the CISA KEV deadline apply to private companies?
The binding deadline technically applies only to U.S. federal civilian executive branch agencies. Private organizations aren’t legally required to meet it, but security teams and cyber insurers widely treat KEV deadlines as an informal benchmark for prioritizing patches.




