Critical CVE-2026-84869 — A ScreenConnect client flaw lets files be transferred and executed during a remote session without host confirmation. CVSS 9.9, on CISA's exploited list. Fixed in 26.6.5; what MSPs and businesses using ScreenConnect need to do.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: During an active ScreenConnect session, the other side can transfer and run files on your computer without the confirmation prompt that's supposed to stop it. Attackers already abuse remote-support tools in tech-support scams and MSP breaches. Upgrade to 26.6.5, then reinstall host clients and update access agents. Cloud servers update automatically; the clients don't.
| CVE | CVE-2026-84869 |
|---|---|
| Component | ScreenConnect client (servers are not affected) |
| Type | Missing authorization / improper privilege management |
| CVSS 3.1 | 9.9 Critical |
| Affected | All versions before 26.6.5 |
| Fixed in | 26.6.5 |
| Exploited? | Yes, CISA KEV 2026-09-11 |
| Workaround | Remove the TransferFiles permission from all roles |
ScreenConnect (formerly ConnectWise Control) is one of the most common remote-support tools, especially among MSPs. Normally, when a technician sends a file and runs it on your machine during a session, you, the host, have to approve it. CVE-2026-84869 lets files be transferred and executed through an active session without that authorization or confirmation in certain circumstances.
ConnectWise is keeping the details private because of how sensitive the bug is, but the risk is clear enough: anyone who gets a session onto a machine, such as a scammer on the phone with an employee or an attacker who has stolen technician credentials, can drop and run malware without a prompt.
On a Windows machine, list installed ScreenConnect clients and their versions:
Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\*,
HKLM:\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* |
Where-Object DisplayName -like '*ScreenConnect*' |
Select-Object DisplayName, DisplayVersion
Anything below 26.6.5 is vulnerable. On the server side, the version is shown in the ScreenConnect admin page.
ConnectWise rates this Priority 1: install within days.
In the ScreenConnect admin, go to the security/roles settings and untick the TransferFiles permission on every role. Technicians lose file transfer until you update, but the attack path is closed.
Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.