Security.io Intelligence DeskSunday, 13 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekend Intelligence Edition
Free to readers
Supported by underwriters
Vulnerability Management · Executive briefing

ScreenConnect joins KEV: check clients and remote-session evidence

CISA’s Friday action put an already patched ScreenConnect client flaw into the known-exploited queue, requiring on-premises operators and MSPs to prove both version state and active-session integrity.

Vulnerability ManagementEndpoint SecurityThird-Party Risk
Why it is in today’s brief

The underlying issue was disclosed on 3 September and patched on 8 September; the new event is CISA’s 11 September KEV addition and 14 September due date. It warrants a second vulnerability slot because ScreenConnect is a privileged remote-support control plane, creating a distinct client-session and third-party assurance decision from GitLab’s unauthenticated server file-read exposure.

Read first

ConnectWise released ScreenConnect 26.6.5 for CVE-2026-84869 after an earlier mitigation notice. CISA added the flaw to KEV on Friday, changing the Monday task from advisory tracking to version proof and session-level compromise review.

Act now

Inventory cloud and on-premises ScreenConnect deployments.

Accountable owner

Head of End-User Computing or MSP Platform Operations with Incident Response

Decision horizon

Today: verify versions and active-session evidence before routine remote-support activity expands the investigation window.

AssessmentHigh confidence
Emerging riskWatch for exploit mechanics, named victims, malicious files, session artefacts or changes to affected client versions.

What happened

On 3 September 2026, ConnectWise published interim mitigation guidance before a security update was generally available. On 8 September 2026, ConnectWise released ScreenConnect 26.6.5. CVE-2026-84869 may allow files to be transferred and executed through an active remote session without authorisation or host confirmation in certain circumstances.

ScreenConnect servers are not impacted; the condition is in the ScreenConnect client and session handling. Cloud deployments were automatically updated, while on-premises deployments must run ScreenConnect 26.6.5 or higher. Temporary mitigation is to remove TransferFiles, or TransferFIlesInSession on legacy versions, from applicable roles and session groups.

On 11 September 2026, CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog with a remediation due date of 14 September 2026. The cited sources did not publish IP addresses, domains, hashes, filenames, exploit requests or named victims. Attribution posture: CISA confirms exploitation of CVE-2026-84869, but the cited sources identify no actor or campaign.

Why this matters now

Remote-support platforms occupy a privileged operational position across endpoints and customer environments. The vulnerable behaviour involves an active session rather than the ScreenConnect server itself, so teams that check only server patch status may misunderstand the exposure. An attacker already present in, or able to abuse, a remote session could use trusted support functionality to transfer and execute files without the expected host confirmation.

MSPs and internal support teams face a compounded assurance problem because one control plane can reach many managed systems. Cloud deployments were automatically updated, but organisations still need evidence that on-premises instances and clients reached the corrected release. Where patching was delayed, temporary permission changes reduce opportunity but do not establish that earlier sessions were clean.

The decision for security leaders

Assign remote-support platform ownership at control-plane level. Require an inventory spanning internal instances, MSP-managed tenants, embedded RMM integrations and off-maintenance deployments. Cloud-hosted status should be verified rather than assumed, while every on-premises deployment needs authenticated version evidence from the instance owner.

Treat patching and session review as separate workstreams. Incident response should define suspicious transfer and execution criteria, preserve relevant logs and determine whether any unexpected files reached managed endpoints. Temporary permission removal must have an expiry tied to deployment of the corrected client, not become an undocumented permanent workaround.

Evidence of closure

  • Deployment inventory records hosting model and authenticated ScreenConnect version.
  • Every on-premises instance reports ScreenConnect 26.6.5 or higher.
  • Session review documents disposition of unexpected transfer or execution events.
  • Temporary permission exceptions have owners and patch-linked expiry dates.

The Security.io assessment

The Friday KEV addition is the material change. ConnectWise had already published the issue and released a fix, but CISA’s action now establishes exploitation and removes the basis for deferring remediation solely because exploit details remain unpublished. ScreenConnect’s reach into endpoints and customer environments raises consequence even though the server component is not affected.

The active-session requirement narrows the exposure compared with an unauthenticated server compromise, but it does not make the issue routine. Organisations with tightly controlled session initiation, least-privilege roles and complete logging can bound risk more effectively than those with shared accounts, persistent access and broad file-transfer permissions. No cited source identifies victims, malicious artefacts or actor intent.

Questions for the morning meeting

  • Which on-premises ScreenConnect deployments remain below 26.6.5?
  • Can logs identify unexpected file-transfer or execution activity in active sessions?
  • Are remote-support permissions narrower than the default operational role design?

Related intelligence

Shared decision context

Appointments, dinners & sponsored intelligence

Current paid placements · clearly separated
Open calendar
Sponsor's Notice · Security.io

Private CISO Roundtable: The 2027 Security Agenda

A closed-door, vendor-neutral discussion for senior security leaders hosted by Security.io.

Request details →
Invitation only
Sponsor's Notice · Security.io

Security.io CISO Dinner: Decisions That Cannot Wait

An invitation-only dinner for CISOs and deputies focused on consequential security decisions.

Request an invitation →
Black Hat week
Paid Placement · Security.io

Security.io at Black Hat: Executive Intelligence Dinner

A private dinner and briefing for security leaders during Black Hat week.

Join the interest list →