CVE- 2026-84869 affects ConnectWise ScreenConnect and has been exploited in the wild, prompting emergency patching. The vulnerability allows unauthorized attackers to transfer and execute malicious files during active remote sessions, effectively bypassing the intended role-based access controls in the client component. ConnectWise confirms that all unpatched on-premise ScreenConnect installations are impacted, with a near-maximum CVSS base score of 9.9. CISA has added the flaw to its Known Exploited Vulnerabilities catalog following observed exploitation.
Administrators should upgrade to ScreenConnect 26.6.5 to fix the faulty authorization logic. If immediate patching is not feasible, a temporary mitigation is available: in the security settings, explicitly deselect the TransferFiles permission across all session groups, effectively restricting file transfers within active sessions. Following either patch or mitigation, it is advised to reinstall host clients to ensure complete protection.
The advisory aligns with CISA’s alert on KEV, highlighting the active risk to managed service providers and downstream corporate networks that rely on ScreenConnect for remote support. The report notes the vulnerability’s impact as a guest-to-host file execution via file-transfer actions, emphasising the critical supply-chain risk posed by compromise of a central remote-access tool. Evidence of exploitation underpins the urgency of remediation, with guidance to review vendor advisories and apply mitigations promptly.