Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

CVE-2026-84869: ConnectWise ScreenConnect Client Lets Files Run Without Approval (Exploited)

Critical CVE-2026-84869 — A ScreenConnect client flaw lets files be transferred and executed during a remote session without host confirmation. CVSS 9.9, on CISA's exploited list. Fixed in 26.6.5; what MSPs and businesses using ScreenConnect need to do.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: During an active ScreenConnect session, the other side can transfer and run files on your computer without the confirmation prompt that's supposed to stop it. Attackers already abuse remote-support tools in tech-support scams and MSP breaches. Upgrade to 26.6.5, then reinstall host clients and update access agents. Cloud servers update automatically; the clients don't.

CVECVE-2026-84869
ComponentScreenConnect client (servers are not affected)
TypeMissing authorization / improper privilege management
CVSS 3.19.9 Critical
AffectedAll versions before 26.6.5
Fixed in26.6.5
Exploited?Yes, CISA KEV 2026-09-11
WorkaroundRemove the TransferFiles permission from all roles

What the bug is

ScreenConnect (formerly ConnectWise Control) is one of the most common remote-support tools, especially among MSPs. Normally, when a technician sends a file and runs it on your machine during a session, you, the host, have to approve it. CVE-2026-84869 lets files be transferred and executed through an active session without that authorization or confirmation in certain circumstances.

ConnectWise is keeping the details private because of how sensitive the bug is, but the risk is clear enough: anyone who gets a session onto a machine, such as a scammer on the phone with an employee or an attacker who has stolen technician credentials, can drop and run malware without a prompt.

Who needs to act

  • MSPs and IT departments running ScreenConnect (cloud or on-prem): update the server, then make sure every deployed client and access agent is updated.
  • Businesses whose MSP uses ScreenConnect: ask your provider to confirm they’re on 26.6.5 and have updated the agents on your machines.
  • Everyone: if ScreenConnect is installed on a PC and nobody knows why, remove it. Unexplained remote-access tools are a common sign of a past scam or intrusion.

Am I affected?

On a Windows machine, list installed ScreenConnect clients and their versions:

Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\*,
  HKLM:\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* |
  Where-Object DisplayName -like '*ScreenConnect*' |
  Select-Object DisplayName, DisplayVersion

Anything below 26.6.5 is vulnerable. On the server side, the version is shown in the ScreenConnect admin page.

How to patch

  1. Cloud-hosted: ConnectWise updates the server automatically. You still need to reinstall host clients and update access agents afterwards. That’s where the bug lives.
  2. On-premises: download 26.6.5 from the ScreenConnect portal (valid license required), upgrade the server, then push updated agents.
  3. Spot-check a few endpoints with the PowerShell above.

ConnectWise rates this Priority 1: install within days.

If you can’t update right away

In the ScreenConnect admin, go to the security/roles settings and untick the TransferFiles permission on every role. Technicians lose file transfer until you update, but the attack path is closed.

Signs of abuse

  • Review ScreenConnect session and audit logs for file transfers and command runs you can’t match to a ticket.
  • Look for unexpected executables in user Downloads, Temp, and ScreenConnect’s own file-transfer folders.
  • Watch for new remote-access tools (AnyDesk, other RMMs) appearing on endpoints after a session. Attackers like to add a second way back in.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories