ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
ConnectWise has released a critical patch to address a vulnerability in ScreenConnect, a remote access and support tool, that’s been actively exploited in worm-like attacks. The flaw allows unauthorized file transfer and execution, leading to the deployment of malicious scripts to compromise connected systems. CISA has added the vulnerability to its KEV catalog, emphasizing the urgency of patching.
ConnectWise has released a critical patch to address a vulnerability in ScreenConnect, a remote access and support tool, that’s been actively exploited in worm-like attacks. The flaw allows unauthorized file transfer and execution, leading to the deployment of malicious scripts to compromise connected systems. CISA has added the vulnerability to its KEV catalog, emphasizing the urgency of patching.
Tracked as CVE-2026-84869 (CVSS score of 9.9/10), the security defect is described as a missing authorization and improper privilege management issue. The vulnerability creates “a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances,” ConnectWise explains in its advisory.
In early September, cybersecurity firm Huntress warned that the vulnerability has been exploited in the wild since August 20. Hackers used social engineering to trick victims into executing rogue ScreenConnect clients, which then checked for active sessions to push the VBScript payload to connected targets. As part of the observed incidents, a modified ScreenConnect instance was used to deploy four VBScript files designed to establish persistence and propagate to other ScreenConnect clients.
ConnectWise resolved the flaw in ScreenConnect version 26.6.5 and urged users to apply the fixes as soon as possible. As a temporary mitigation, it recommends disabling the TransferFiles permission in ScreenConnect. “The ScreenConnect 26.6.5 patch includes updates to strengthen client and session handling for file-transfer and file-execution actions,” ConnectWise notes.
On Friday, the US cybersecurity agency CISA added CVE-2026-84869 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, as mandated by BOD 26-04.