As reported by BleepingComputer, CISA has confirmed that attackers are actively exploiting CVE-2026-84869, a critical-severity vulnerability in ConnectWise ScreenConnect that combines improper privilege management with missing authorization to enable unauthorized file transfer and execution through active remote sessions. This is not a theoretical risk — it is happening now, and the exposure surface is significant.
Vulnerability Snapshot
| CVE | CVE-2026-84869 |
| Severity | Critical |
| Vendor / Product | ConnectWise ScreenConnect (client component) |
| Affected Versions | ScreenConnect prior to 26.6.5 |
| Patched Version | ScreenConnect 26.6.5 and later |
| Attack Complexity | Low — no user interaction required |
| Active Exploitation | Yes — CISA KEV catalog, 3-day federal remediation mandate |
| Interim Mitigation | Disable TransferFiles permissions (recommended by ConnectWise since Sept 7) |
Why This Matters
ScreenConnect is a staple tool for managed service providers (MSPs) and internal IT teams globally — ConnectWise serves over 100,000 IT providers. Remote access platforms are inherently high-trust: they sit at the intersection of endpoint control, credential access, and lateral movement. When a flaw like this enables unauthorized file execution through an active session, an attacker who gains even basic foothold access can escalate to full system compromise without re-authentication or triggering host-side confirmation prompts.
The threat landscape compounds the urgency. Shadowserver identifies over 1,000 internet-exposed, unpatched ScreenConnect instances — 758 in North America alone. Since 2024, CISA has flagged four separate ScreenConnect vulnerabilities as actively exploited, two of which were subsequently leveraged in ransomware operations. Nation-state actors including Kimsuky have previously targeted this platform. The pattern is clear: ScreenConnect is a recurring soft target, and threat actors are cycling through its weaknesses faster than many organizations are patching them.
The convergence of remote access tooling, MSP supply chains, and repeated exploitation makes this vulnerability a strategic risk — not just a tactical patching task.
Who Is Most at Risk
Immediate Actions
- Patch immediately to ScreenConnect 26.6.5 or later. If patching requires change windows, apply the interim mitigation now.
- Disable TransferFiles permissions across all session policies until patching is complete and validated.
- Audit internet exposure — enumerate all ScreenConnect instances (including those managed by MSP partners) and confirm none are reachable without VPN or zero-trust gating.
- Hunt for indicators of compromise — review session logs for unauthorized file transfers, unexpected process execution chains, and sessions originating from anomalous IPs or outside business hours.
- Enforce least-privilege session policies — restrict which accounts can initiate file transfer and execution, and require host confirmation for elevated actions.
- Notify downstream clients if you are an MSP — your exposure is their exposure.
Shield53 Recommendations
This is the fourth actively exploited ScreenConnect flaw in under three years. Treat remote access platforms as tier-zero infrastructure: they require the same hardening, monitoring, and patch cadence as domain controllers or identity providers. Specifically:
- Mandate patch SLAs of 72 hours or less for critical vulnerabilities in remote management tools — align with CISA's binding operational directive timelines even if you are not a federal agency.
- Segment remote access infrastructure behind VPN or zero-trust network access; eliminate direct internet exposure unless absolutely necessary and explicitly justified.
- Deploy session recording and real-time alerting for file transfer and remote execution events. Anomaly detection on session metadata is your best detection lever for this class of abuse.
- Reassess vendor risk — if your organization or MSP relies on ScreenConnect, escalate this to vendor risk management discussions. Repeated critical flaws warrant contractual patch timelines and security attestations.
- Tabletop the ransomware scenario — given that two prior ScreenConnect CVEs were used in ransomware campaigns, validate that your incident response and backup recovery procedures assume remote access tool compromise as an initial access vector.
The window between disclosure, active exploitation, and organizational patching is where breaches happen. With CISA's three-day clock ticking and Shadowserver mapping exposed instances, the message to attackers and defenders alike is the same: the targets are visible, and time is short.