CISA KEV Alert 11 Sept 2026, 20:32 UTC

Actively Exploited ScreenConnect Flaw Enables Unauthorised File Execution

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA has added CVE-2026-84869 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects ConnectWise ScreenConnect and is named the ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability. It may allow attackers to transfer and execute files through active remote sessions without authorisation or host confirmation.

The flaw combines improper privilege management with missing authorisation controls. An attacker may use an active remote session to perform file-transfer and execution actions without the required permission or confirmation from the host. NVD assigns the vulnerability a CVSS score of 9.9, rated Critical. The available data does not confirm whether a patch is available; patch status is listed as unknown.

CISA’s KEV listing confirms that attackers are actively exploiting this vulnerability. The available information does not identify ransomware campaign use. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 14 September 2026.

CISA requires organisations to apply mitigations in accordance with ConnectWise’s instructions, while following CISA’s BOD 26-04 guidance on prioritising security updates based on risk and its Forensics Triage Requirements. Agencies should follow the applicable BOD 26-04 guidance for cloud services or discontinue use of ScreenConnect if mitigations are unavailable. Stakeholders must assess each asset’s internet exposure and comply with BOD 26-04 patching guidance. FCEB agencies are directly affected, but all organisations should review their exposure.

See the NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT