Skip to content

Security1 publisher2 min readPublished

CVE-2026-84869 lets an attacker run files inside a live ScreenConnect session

The bug lets files be pushed and executed through a remote session the host already approved, and CISA says attackers are doing it now. It is ScreenConnect's fourth entry on the KEV catalog since 2024.

The Watch · Security desk

Illustration accompanying CVE-2026-84869 lets an attacker run files inside a live ScreenConnect session

What happened

  • CISA added CVE-2026-84869, a CVSS 9.9 flaw in ConnectWise ScreenConnect, to its known exploited vulnerabilities catalog on Sept. 11 and said it was being exploited in the wild.
  • The agency describes it as improper privilege management and missing authorization that lets attackers transfer and execute files via an active remote session without authorization or host confirmation.
  • ConnectWise released the patch on Sept. 8.
  • It is the fourth ScreenConnect flaw CISA has put on KEV since 2024, and two of those four were exploited by ransomware groups.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure One compromised MSP instance reaches every client that relies on it for access. Keeper Security's Shane Barney said the risk compounds for service providers.
  • decision A monthly or quarterly cycle is slower than the interval this flaw took to reach KEV, so operators have to decide between an out-of-band push and running on the interim mitigations.
  • contradiction CISA's active-session framing and Barney's account of the 9.9 rating disagree on whether an attacker needs credentials. That disagreement decides how urgent an internet-facing instance is.
  • precedent Remote-access tooling is now hunted on a schedule, per Cobalt's Andrew Obadiaru, so the next ScreenConnect advisory should be treated as pre-exploited until proven otherwise.

Three days separated ConnectWise's fix from CISA's confirmation that someone was using the bug [16]. Shane Barney, chief information security officer at Keeper Security, said ransomware gangs monitor the KEV catalog and that once a flaw lands there the patch window becomes exponentially smaller [7]. Half of the ScreenConnect entries added to KEV since 2024 have ransomware attached [17]. CISA did not name who is exploiting this one [18].

The abuse happens inside a session someone already approved, so the host sees no confirmation before files land and execute [2]. "Once you can transfer or execute files inside an active session without authorization, you're not breaking in," said Andrew Obadiaru, vice president and CISO at Cobalt. "You're riding in on credentials the system already trusts" [15]. Obadiaru said ScreenConnect has been a recurring target for both ransomware crews and state-backed groups since 2024 because it is a pre-established, trusted channel into thousands of environments that IT teams already rely on daily [14].

The public record is not consistent about what an attacker needs to begin. CISA's description places the file transfer inside an active remote session [2]. Barney said the flaw "lets attackers with basic privileges transfer and execute arbitrary files without authorization or user interaction" [5]. The rating, he said, followed from "the combination of low complexity, no user interaction and unauthenticated file execution" [6]. An unauthenticated path and a basic-privileges path leave an internet-exposed instance in very different positions.

Barney said the patch belongs "above the standard quarterly or monthly rhythm most operate from" [10]. Not every site can get there this week. For those, he said: "If immediate patching is not possible, segregate ScreenConnect instances from sensitive network segments, disable TransferFiles permissions as a temporary measure and monitor for any exploitation attempts" [9]. Turning off TransferFiles takes away the capability the described attack uses [20].

John Strand, owner at Black Hills Information Security, said the gap between disclosure and active exploitation has gotten short enough that organizations cannot spend weeks testing patches before rolling them into production [12]. "Don't wait, get it patched," said Strand [11]. He also said the case for keeping products like this on-prem is eroding. "There have always been legitimate reasons for keeping certain technologies on-prem, but some of those reasons are starting to disappear pretty quickly in the face of the attack vectors we're seeing today" [13].

What to watch

  • A named ransomware affiliate tied to CVE-2026-84869 would take ScreenConnect to three ransomware-linked KEV entries out of five.
  • A clarification from ConnectWise or CISA on whether exploitation requires an authenticated session settles how exposed unpatched internet-facing instances are.
  • Another ScreenConnect flaw reaching KEV inside the same 24-month window.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories