ConnectWise patches ScreenConnect flaw after worm-like attacks

ConnectWise issued urgent patches for CVE-2026-84869 after attackers exploited a ScreenConnect flaw to transfer and execute files across active remote sessions without authorization.
ConnectWise released urgent updates to fix a critical ScreenConnect vulnerability tracked as CVE-2026-84869 with a CVSS score of 9.9. The company closed the defect in ScreenConnect version 26.6.5 and urged administrators to install the update immediately.
ConnectWise described the issue as a missing authorization and improper privilege management problem that “may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances.” The 26.6.5 update includes changes to client and session handling for file-transfer and file-execution actions.
Cybersecurity firm Huntress reported the vulnerability has been exploited in the wild since August 20. In observed incidents, attackers used social engineering to convince users to run modified ScreenConnect clients. Those clients checked for active remote sessions and pushed a payload of four VBScript files to connected systems.
The four scripts were designed to establish persistence on infected hosts and to propagate to other ScreenConnect clients, producing rapid, worm-like spread. Exploitation depended on an operator or endpoint launching the altered ScreenConnect software, after which attackers used active sessions to move laterally and execute files without Host confirmation. Remote access tools should be included in continuous attack surface management because every active session can become a path for lateral movement.
On Friday, the U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-84869 to its Known Exploited Vulnerabilities catalog and directed federal agencies to install patches within three days under Binding Operational Directive 26-04.
ConnectWise recommended that organizations update to ScreenConnect 26.6.5 or later and offered a temporary mitigation of disabling the TransferFiles permission. Incident responders investigating possible compromise should look for unauthorized ScreenConnect clients, the specific VBScript files Huntress described, unexpected remote-session file transfers, and indicators of persistence or lateral movement.
ScreenConnect is remote access and support software used by managed service providers and internal IT teams. Administrators should apply the patch and follow mitigations to address the reported exploitation.








