Security1 publisher2 min readPublished
ConnectWise patches a ScreenConnect client that can run transferred files without host consent
CVE-2026-84869 affects ScreenConnect clients before 26.6.5. ConnectWise rates it Priority 1 High and tells on-premise partners to treat the update as an emergency change, then reinstall host clients and access agents.
The Watch · Security desk

What happened
- ConnectWise says a condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances.
- Every ScreenConnect version prior to 26.6.5 is impacted, servers are not, and the patch strengthens client and session handling for file-transfer and file-execution actions.
- The on-premise download needs a valid on-premises license, and a license that is out of maintenance has to be upgraded before the latest supported release will install.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- contradiction Cloud tenants are told no action is required and, in the same section, told to reinstall host clients and update access agents after upgrading; the two lines describe very different amounts of work for a fleet.
- cost Lapsed-maintenance on-premise shops pay for a license upgrade before they can apply a patch ConnectWise wants installed within days, so the purchase has to clear before the update can be installed.
- decision An on-premise operator inside a change freeze now chooses between switching off file transfer for all technicians and running pre-26.6.5 clients until the window opens.
The patched code sits in the client [4]. Upgrade an on-premise server, stop there, and every endpoint still running a pre-26.6.5 client keeps the condition; the remediation scales with installed agents [1]. Both remediation paths in the bulletin close with the same pair of steps, reinstall host clients and update access agents [8][14].
ConnectWise files the flaw as Important, a tier its own scale defines as vulnerabilities that could compromise confidential data or other resources but require additional access, privilege or circumstances to do so [6]. ConnectWise did not describe those circumstances, and did not say whether the condition has been exploited [15]. That leaves the priority number, and ConnectWise sets that at 1 High, the tier reserved for vulnerabilities being targeted or at higher risk of being targeted, with updates installed as emergency changes or within days [7].
For shops that cannot move inside a change window, the interim step is a role edit. Administration > Security > Roles, edit each role, review every session group that has permissions assigned, deselect TransferFiles, save, then repeat for each role [9]. Applied across all roles, that stops file transfer for technicians doing legitimate work as well as for anyone abusing a session [2]. ConnectWise wrote that "This is not a substitute for installing the security update." [10]
The download route matters for the slowest cohort. Access to the on-premise update requires a valid on-premises license, and a license out of maintenance has to be upgraded before the latest supported release will install [11][12]. That puts a commercial transaction in front of a Priority 1 patch for anyone who has let maintenance lapse [3]. Automate partners running an integrated on-premise ScreenConnect can pull 26.6.5 from the Automate Product Updates page while their Automate Assurance subscription is active [13].
The bulletin is dated 09/08/2026 [2].
What to watch
- Exploitation detail or indicators added to the 09/08/2026 bulletin would compress the timeline for everyone still on pre-26.6.5 clients.
- Whether the ScreenConnect 26.6 release notes spell out the preconditions ConnectWise did not describe.
- Any clarification on whether cloud access agents update themselves or need the manual reinstall the bulletin asks for.