Back to Blog
CVE-2026-84869: ConnectWise ScreenConnect — Wormable Remote Code Execution (August 2026)
vulnerabilities

CVE-2026-84869: ConnectWise ScreenConnect — Wormable Remote Code Execution (August 2026)

breachwire TeamSep 20, 20262 min read

CVE-2026-84869 — ConnectWise ScreenConnect

CVE-2026-84869 is a critical vulnerability in ConnectWise ScreenConnect remote support software, enabling attackers to transfer and execute files remotely without authorization. The flaw is under active exploitation, with attackers leveraging it for worm-like propagation since August 20, 2026. US CISA has issued a mandatory patch deadline due to the severity and scale of exploitation.

Attack Vector

Attackers exploit a missing authorization check in active ScreenConnect remote sessions, allowing them to upload and execute arbitrary files on connected endpoints. The attack chain involves social engineering to convince users to launch rogue clients, after which malware is propagated to additional hosts via existing remote sessions. No prior authentication or elevated privileges are required once a session is established, making lateral movement rapid and difficult to contain. Indicators of compromise include unexpected file transfers, new client installations, and anomalous remote session activity.

Who Is at Risk

All organizations using ConnectWise ScreenConnect, regardless of deployment type or version, are at risk. The attacks have been observed globally, with confirmed exploitation against ConnectWise customers. Managed service providers (MSPs) and enterprises relying on ScreenConnect for remote support are especially vulnerable due to the software’s widespread access to internal systems.

Patch & Mitigate

  • Patch: Apply the latest ScreenConnect security update released August 2026 immediately. CISA requires patching within three days of advisory.
  • Workaround: Disable remote file transfer and restrict remote session initiation to trusted users until patched.
  • Detect: Review logs for unauthorized file transfers, unexpected client deployments, and anomalous remote session activity since August 20, 2026. Monitor for lateral movement originating from ScreenConnect hosts.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers use social engineering to gain session access and deploy rogue clients.
  • TA0005 — Defense Evasion: Malware execution occurs via trusted remote sessions, bypassing standard controls.
  • TA0007 — Discovery: Attackers enumerate connected clients to propagate malware across the network.

Source: https://www.securityweek.com/connectwise-patches-screenconnect-vulnerability-exploited-in-worm-like-attacks/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: