Back to Blog
CVE-2026-84869: ConnectWise ScreenConnect — Zero-Day Enables File Transfer (September 2026)
vulnerabilities

CVE-2026-84869: ConnectWise ScreenConnect — Zero-Day Enables File Transfer (September 2026)

breachwire TeamSep 12, 20262 min read

CVE-2026-84869 — ConnectWise ScreenConnect

CVE-2026-84869 is a critical severity zero-day vulnerability in ConnectWise ScreenConnect, actively exploited to permit unauthorized file transfers and code execution during live remote access sessions. ConnectWise confirmed exploitation on September 3, 2026, and released a patch five days later. The vulnerability’s exploitation risk is high due to prior targeting of ConnectWise by advanced threat actors.

Attack Vector

Attackers leverage this flaw during active ScreenConnect sessions, bypassing authentication controls to upload or execute arbitrary files on remote systems. No user interaction is required beyond an active session, making exploitation trivial for attackers with session access. The vulnerability allows lateral movement or malware deployment directly into customer environments. No specific IOCs were released, but defenders should monitor for anomalous file transfers or unexpected process launches during remote sessions.

Who Is at Risk

All organizations running ConnectWise ScreenConnect prior to client version 26.6.5 are exposed. Both on-premises and cloud deployments are affected globally. ConnectWise customers are specifically at risk, and the attack surface includes any environment where ScreenConnect is used for remote support or administration.

Patch & Mitigate

  • Patch: Upgrade to ScreenConnect client version 26.6.5 or later immediately. Patch was released September 8, 2026.
  • Workaround: No official workaround is available; disabling remote sessions is the only temporary risk reduction.
  • Detect: Audit logs for unexpected file transfers or process executions during remote sessions. Look for anomalous session activity or files appearing on endpoints without user initiation.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers exploit the vulnerability to gain an initial foothold via remote session abuse.
  • T1105 — Ingress Tool Transfer: The flaw enables unauthorized file transfers into the target environment.
  • T1059 — Command and Scripting Interpreter: Attackers may execute arbitrary code or scripts during the session.

Source: https://www.csoonline.com/article/4221263/connectwise-patches-critical-screenconnect-authentication-failure-after-five-days-2.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: