CISA confirms threat actors are exploiting CVE-2026-84869, a critical missing-authorization flaw in ConnectWise ScreenConnect clients, in live attacks. The issue allows low-privilege users to transfer and run files through active remote sessions without host approval, and federal agencies have three days to remediate. More than 1,000 internet-exposed instances remain unpatched, according to Shadowserver.
How the attack works
The defect impacts ScreenConnect clients and combines improper privilege management with missing authorization checks. According to CISA, it may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.
In practical terms, the flow described in the source material is:
- An attacker holds basic privileges on a ScreenConnect deployment.
- The attacker joins or leverages an active remote session.
- File transfer and execution functions are invoked without additional authorization or confirmation from the host.
- No user interaction is needed, and attack complexity is low.
CISA warned that These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Both financially-motivated and state-backed groups routinely target ScreenConnect flaws of this type.
Interim mitigation and patch
ConnectWise published temporary protective guidance on September 7, recommending that administrators disable TransferFiles permissions to interrupt potential abuse paths.
The permanent fix is available in ScreenConnect 26.6.5 and later. Organizations should upgrade clients to 26.6.5 or a newer release and then re-enable needed functionality only after confirming the update.
Background on the initial disclosure is available in ConnectWise warning about the unpatched flaw, with vulnerability details in the NVD entry for CVE-2026-84869.
Federal directive and current exposure
CISA placed the flaw in its catalog of actively exploited flaws on Friday and directed U.S. federal agencies to protect their systems against ongoing attacks within three days. Details are in the CISA alert adding three flaws to the KEV catalog and the CISA KEV entry for CVE-2026-84869.
Internet watchdog Shadowserver currently tracks over 1,000 ScreenConnect instances still unpatched and exposed to attacks online, with 758 in North America and 180 in Europe.
ConnectWise provides services to more than 100,000 IT providers worldwide, with many managed service providers (MSPs) and IT teams using its ScreenConnect remote access platform for troubleshooting, patching, and system maintenance, expanding the potential impact.
Prior ScreenConnect exploitation
Since 2024, CISA has flagged four ScreenConnect security issues as actively exploited, two of which have also been abused in ransomware attacks. A full vendor listing is available in the CISA KEV filter for ConnectWise.
Earlier incidents include:
- CVE-2024-1709 in 2024, exploited by the North Korean-backed Kimsuky hacking group and several ransomware gangs, described further in ScreenConnect flaws used to drop ToddlerShark malware and ScreenConnect RCE flaw exploited in ransomware attacks.
- CVE-2025-3935, a ViewState flaw used in code injection attacks where suspected state-sponsored hackers breached ConnectWise systems and accessed the cloud-based instances of a limited number of customers, after which ConnectWise rotated digital code-signing certificates. See ConnectWise rotating certificates over security concerns and ConnectWise breach linked to nation-state hackers.
- CVE-2026-3564 in March, a cryptographic signature verification vulnerability that could allow attackers to hijack unpatched ScreenConnect servers, covered in ConnectWise patches flaw allowing ScreenConnect hijacking.
Technical background
This section is general educational background about this vulnerability class, not specifics of CVE-2026-84869 or the current incident.
Missing-authorization and improper privilege management flaws occur when a server or client exposes a sensitive operation but fails to verify that the caller holds the required role for that specific object or session. Remote-access tools are especially sensitive because file transfer and remote execution are legitimate features for administrators.
A generic illustrative pattern, not code from this incident:
# GENERIC EXAMPLE - not the ScreenConnect implementation
def handle_file_transfer(session, user, file_data):
# Vulnerable if only authentication is checked:
if not user.is_authenticated:
return False
# Secure implementations must also check authorization:
# if not user.can("TransferFiles", session):
# return False
return session.write_file(file_data)
Defenders generally reduce risk by enforcing per-session authorization checks, requiring host confirmation for file operations, logging transfer and execution events, restricting remote-access hosts from the public internet, and applying least privilege to roles.