CONNECTWISE has released urgent patches for a critical vulnerability in its ScreenConnect remote-access and support software, which has been exploited in worm-like attacks. Tracked as CVE-2026-84869 and rated 9.9/10, the flaw involves missing authorisation and improper privilege management. ConnectWise says it can allow files to be transferred and executed through an active remote session without authorisation or Host confirmation in certain circumstances.
Security firm Huntress reported in early September that exploitation had been occurring in the wild since 20 August. In observed incidents, attackers used a modified ScreenConnect instance to deploy four VBScript files intended to establish persistence and spread to other ScreenConnect clients. Social engineering was used to persuade victims to execute rogue ScreenConnect clients; those clients then checked for active sessions and pushed the VBScript payloads to connected targets.
ConnectWise fixed the issue in ScreenConnect version 26.6.5, which strengthens client and session handling for file-transfer and file-execution actions. The company advises customers to apply the update as soon as possible and recommends disabling the TransferFiles permission as a temporary mitigation. On Friday, the US Cybersecurity and Infrastructure Security Agency added CVE-2026-84869 to its Known Exploited Vulnerabilities catalogue, requiring US federal agencies to address it within three days under BOD 26-04.