What happened
On 3 September 2026, ConnectWise published interim mitigation guidance before a security update was generally available. On 8 September 2026, ConnectWise released ScreenConnect 26.6.5. CVE-2026-84869 may allow files to be transferred and executed through an active remote session without authorisation or host confirmation in certain circumstances.
ScreenConnect servers are not impacted; the condition is in the ScreenConnect client and session handling. Cloud deployments were automatically updated, while on-premises deployments must run ScreenConnect 26.6.5 or higher. Temporary mitigation is to remove TransferFiles, or TransferFIlesInSession on legacy versions, from applicable roles and session groups.
On 11 September 2026, CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog with a remediation due date of 14 September 2026. The cited sources did not publish IP addresses, domains, hashes, filenames, exploit requests or named victims. Attribution posture: CISA confirms exploitation of CVE-2026-84869, but the cited sources identify no actor or campaign.
Why this matters now
Remote-support platforms occupy a privileged operational position across endpoints and customer environments. The vulnerable behaviour involves an active session rather than the ScreenConnect server itself, so teams that check only server patch status may misunderstand the exposure. An attacker already present in, or able to abuse, a remote session could use trusted support functionality to transfer and execute files without the expected host confirmation.
MSPs and internal support teams face a compounded assurance problem because one control plane can reach many managed systems. Cloud deployments were automatically updated, but organisations still need evidence that on-premises instances and clients reached the corrected release. Where patching was delayed, temporary permission changes reduce opportunity but do not establish that earlier sessions were clean.
The decision for security leaders
Assign remote-support platform ownership at control-plane level. Require an inventory spanning internal instances, MSP-managed tenants, embedded RMM integrations and off-maintenance deployments. Cloud-hosted status should be verified rather than assumed, while every on-premises deployment needs authenticated version evidence from the instance owner.
Treat patching and session review as separate workstreams. Incident response should define suspicious transfer and execution criteria, preserve relevant logs and determine whether any unexpected files reached managed endpoints. Temporary permission removal must have an expiry tied to deployment of the corrected client, not become an undocumented permanent workaround.
Evidence of closure
- Deployment inventory records hosting model and authenticated ScreenConnect version.
- Every on-premises instance reports ScreenConnect 26.6.5 or higher.
- Session review documents disposition of unexpected transfer or execution events.
- Temporary permission exceptions have owners and patch-linked expiry dates.
The Security.io assessment
The Friday KEV addition is the material change. ConnectWise had already published the issue and released a fix, but CISA’s action now establishes exploitation and removes the basis for deferring remediation solely because exploit details remain unpublished. ScreenConnect’s reach into endpoints and customer environments raises consequence even though the server component is not affected.
The active-session requirement narrows the exposure compared with an unauthenticated server compromise, but it does not make the issue routine. Organisations with tightly controlled session initiation, least-privilege roles and complete logging can bound risk more effectively than those with shared accounts, persistent access and broad file-transfer permissions. No cited source identifies victims, malicious artefacts or actor intent.
Questions for the morning meeting
- Which on-premises ScreenConnect deployments remain below 26.6.5?
- Can logs identify unexpected file-transfer or execution activity in active sessions?
- Are remote-support permissions narrower than the default operational role design?