A critical vulnerability in the ConnectWise ScreenConnect platform is being actively exploited, according to a warning from the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability, tracked as CVE-2026-84869, has been added to the agency’s Known Exploited Vulnerabilities Catalog, and CISA is requiring U.S. federal agencies to secure their systems within three days.
The issue involves a lack of authorization validation and improper privilege management. According to the published description, it allows an attacker with basic privileges to transfer or execute files through an active remote access session without appropriate authorization or host confirmation. The attacks do not require high complexity or user interaction.
Affected Version and Available Remediation
ConnectWise released a fix for the vulnerability in ScreenConnect 26.6.5 and later versions. On September 7, the company had shared temporary mitigation measures, including disabling TransferFiles permissions to reduce the likelihood of exploitation before applying the update.
This sequence indicates that disabling file transfers is not a substitute for patching, but rather a temporary measure to reduce the attack surface. The primary action is to update ScreenConnect to a version that includes the fix, while reviewing exposed systems for indicators of compromise, an issue for which the source provided no additional operational details.
Indicators of Widespread Exposure
Shadowserver is tracking more than 1,000 ScreenConnect instances that remain unpatched and exposed to attacks on the internet. The largest number is concentrated in North America, with 758 instances, followed by Europe with 180 instances.
Companies that provide IT services and internal IT teams use the ScreenConnect platform for remote access to troubleshoot problems, apply updates, and perform maintenance. ConnectWise says it provides services to more than 100,000 technology service providers worldwide, meaning exploitation of a vulnerability in the platform could potentially affect a large number of environments that rely on remote support and management services.
Why Does This Matter?
The importance of the vulnerability lies not only in its theoretical severity, but also in its transition to observed exploitation, while more than 1,000 instances remain exposed. ScreenConnect’s previous track record also shows that the platform has been targeted by financially motivated criminal groups and state-sponsored actors; the CVE-2024-1709 vulnerability was exploited in 2024 by the North Korean Kimsuky group and several ransomware gangs.
Since 2024, CISA has added four ScreenConnect vulnerabilities to its Known Exploited Vulnerabilities Catalog, two of which were also used in ransomware attacks. In March, ConnectWise addressed a vulnerability in cryptographic signature validation, tracked as CVE-2026-3564, which could have enabled the takeover of unpatched ScreenConnect servers. The company also disclosed last year that breaches attributed to state-sponsored actors had exploited a ViewState flaw through code injection and accessed cloud instances belonging to a limited number of customers.
In practice, ScreenConnect users should prioritize updating and should not rely solely on temporary mitigation measures, while keeping in mind that placing the system behind an enterprise environment does not eliminate the risk of exploitation if the interface remains exposed or permissions are broader than necessary.