Vulnerability
Published 2026-09-03
Verified 2026-09-19

ConnectWise ScreenConnect CVE-2026-84869 (CVSS 9.9); patch client 26.6.5; Huntress rogue clients

ConnectWise ScreenConnect™ 26.6.5 Security Patch bulletin (8 September 2026, Priority 1 High) assigns CVE-2026-84869 for a client-side condition that may allow files to be transferred and executed through an active remote Support/Access session without authorisation or Host confirmation. ScreenConnect servers are not impacted. CWE-862 Missing Authorization / CWE-269 Improper Privilege Management; CVSS 3.1 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Affected: ScreenConnect versions prior to 26.6.5. Remediation: upgrade to 26.6.5 or later, then reinstall Host clients and update Access agents (Cloud servers already remediated per vendor). Interim mitigation until clients are refreshed: remove TransferFiles (and TransferFilesInSession on legacy) from applicable roles/session groups — not a substitute for the patch. Earlier 3 September Guest File Transfer Advisory and Huntress late-August worm-like rogue ScreenConnect client chain (Quick Assist → wscript → VBScripts / User Run Key) remain relevant context; Shadowserver has tracked thousands of internet-exposed instances. CISA KEV listed CVE-2026-84869 on 11 September 2026 (dateAdded 2026-09-11; catalogVersion 2026.09.11); this card remains the single ScreenConnect file-transfer topic. Distinct from faronics-deploy-screenconnect-20260831. Primary: ConnectWise 2026-09-08 bulletin.

Product
ConnectWise ScreenConnect (client / session file-transfer and execution; servers not impacted)
Versions
Prior to 26.6.5 (Cloud and On-Premise clients); remediate 26.6.5+
CVSS
Exploited in Australia?
unknown
Patch to
Upgrade ScreenConnect to 26.6.5+; reinstall Host clients / update Access agents; until then remove TransferFiles permissions

Primary: ConnectWise — ScreenConnect 26.6.5 Security Patch (8 Sep 2026) · Vendor: ConnectWise Trust Center bulletin · CVE: CVE-2026-84869 · Huntress rogue ScreenConnect; earlier BC/SW 7 Sep advisory coverage

vulnerabilities identity network