Skip to content

Security1 publisher2 min readPublished

ConnectWise patches a ScreenConnect client that can run transferred files without host consent

CVE-2026-84869 affects ScreenConnect clients before 26.6.5. ConnectWise rates it Priority 1 High and tells on-premise partners to treat the update as an emergency change, then reinstall host clients and access agents.

The Watch · Security desk

Illustration accompanying ConnectWise patches a ScreenConnect client that can run transferred files without host consent

What happened

  • ConnectWise says a condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances.
  • Every ScreenConnect version prior to 26.6.5 is impacted, servers are not, and the patch strengthens client and session handling for file-transfer and file-execution actions.
  • The on-premise download needs a valid on-premises license, and a license that is out of maintenance has to be upgraded before the latest supported release will install.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • contradiction Cloud tenants are told no action is required and, in the same section, told to reinstall host clients and update access agents after upgrading; the two lines describe very different amounts of work for a fleet.
  • cost Lapsed-maintenance on-premise shops pay for a license upgrade before they can apply a patch ConnectWise wants installed within days, so the purchase has to clear before the update can be installed.
  • decision An on-premise operator inside a change freeze now chooses between switching off file transfer for all technicians and running pre-26.6.5 clients until the window opens.

The patched code sits in the client [4]. Upgrade an on-premise server, stop there, and every endpoint still running a pre-26.6.5 client keeps the condition; the remediation scales with installed agents [1]. Both remediation paths in the bulletin close with the same pair of steps, reinstall host clients and update access agents [8][14].

ConnectWise files the flaw as Important, a tier its own scale defines as vulnerabilities that could compromise confidential data or other resources but require additional access, privilege or circumstances to do so [6]. ConnectWise did not describe those circumstances, and did not say whether the condition has been exploited [15]. That leaves the priority number, and ConnectWise sets that at 1 High, the tier reserved for vulnerabilities being targeted or at higher risk of being targeted, with updates installed as emergency changes or within days [7].

For shops that cannot move inside a change window, the interim step is a role edit. Administration > Security > Roles, edit each role, review every session group that has permissions assigned, deselect TransferFiles, save, then repeat for each role [9]. Applied across all roles, that stops file transfer for technicians doing legitimate work as well as for anyone abusing a session [2]. ConnectWise wrote that "This is not a substitute for installing the security update." [10]

The download route matters for the slowest cohort. Access to the on-premise update requires a valid on-premises license, and a license out of maintenance has to be upgraded before the latest supported release will install [11][12]. That puts a commercial transaction in front of a Priority 1 patch for anyone who has let maintenance lapse [3]. Automate partners running an integrated on-premise ScreenConnect can pull 26.6.5 from the Automate Product Updates page while their Automate Assurance subscription is active [13].

The bulletin is dated 09/08/2026 [2].

What to watch

  • Exploitation detail or indicators added to the 09/08/2026 bulletin would compress the timeline for everyone still on pre-26.6.5 clients.
  • Whether the ScreenConnect 26.6 release notes spell out the preconditions ConnectWise did not describe.
  • Any clarification on whether cloud access agents update themselves or need the manual reinstall the bulletin asks for.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories