ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
A critical vulnerability (CVE-2026-84869) in ConnectWise ScreenConnect remote access software allows unauthorized file transfer and execution through active remote sessions. Exploited in worm-like attacks since August 2026, attackers used social engineering to deploy VBScript payloads for persistence and propagation. ConnectWise released a patch in version 26.6.5 and recommends disabling the TransferFiles permission as a temporary mitigation. The US CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging rapid patching.
AI Analysis
Technical Summary
CVE-2026-84869 is a missing authorization and improper privilege management vulnerability in ScreenConnect that permits attackers to transfer and execute files without host confirmation during active remote sessions. Exploitation has been observed in the wild since August 20, 2026, involving modified ScreenConnect clients deploying VBScript files to establish persistence and propagate to other clients. ConnectWise patched the vulnerability in ScreenConnect version 26.6.5, which strengthens client and session handling for file-transfer and execution actions. Temporary mitigation includes disabling the TransferFiles permission. CISA has mandated patching within three days for federal agencies.
Potential Impact
The vulnerability enables unauthorized file transfer and execution via active remote sessions, facilitating worm-like propagation and persistence of malicious code across ScreenConnect clients. This can lead to widespread compromise within affected environments if exploited. The high CVSS score of 9.9 underscores the critical severity of the flaw.
Mitigation Recommendations
ConnectWise has released an official patch in ScreenConnect version 26.6.5 that addresses the vulnerability by enhancing client and session handling for file transfer and execution. Users should apply this patch immediately. As a temporary mitigation, disabling the TransferFiles permission in ScreenConnect is recommended until the patch is applied. CISA mandates patching within three days for federal agencies. No other mitigations are indicated by the vendor advisory.
ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
Description
A critical vulnerability (CVE-2026-84869) in ConnectWise ScreenConnect remote access software allows unauthorized file transfer and execution through active remote sessions. Exploited in worm-like attacks since August 2026, attackers used social engineering to deploy VBScript payloads for persistence and propagation. ConnectWise released a patch in version 26.6.5 and recommends disabling the TransferFiles permission as a temporary mitigation. The US CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging rapid patching.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-84869 is a missing authorization and improper privilege management vulnerability in ScreenConnect that permits attackers to transfer and execute files without host confirmation during active remote sessions. Exploitation has been observed in the wild since August 20, 2026, involving modified ScreenConnect clients deploying VBScript files to establish persistence and propagate to other clients. ConnectWise patched the vulnerability in ScreenConnect version 26.6.5, which strengthens client and session handling for file-transfer and execution actions. Temporary mitigation includes disabling the TransferFiles permission. CISA has mandated patching within three days for federal agencies.
Potential Impact
The vulnerability enables unauthorized file transfer and execution via active remote sessions, facilitating worm-like propagation and persistence of malicious code across ScreenConnect clients. This can lead to widespread compromise within affected environments if exploited. The high CVSS score of 9.9 underscores the critical severity of the flaw.
Mitigation Recommendations
ConnectWise has released an official patch in ScreenConnect version 26.6.5 that addresses the vulnerability by enhancing client and session handling for file transfer and execution. Users should apply this patch immediately. As a temporary mitigation, disabling the TransferFiles permission in ScreenConnect is recommended until the patch is applied. CISA mandates patching within three days for federal agencies. No other mitigations are indicated by the vendor advisory.
Technical Details
- Classification
- {"confidence":0.89,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/connectwise-patches-screenconnect-vulnerability-exploited-in-worm-like-attacks/","fetched":true,"fetchedAt":"2026-09-14T08:31:39.330Z","wordCount":916}
Threat ID: 6aa7b0eb55bf5e2cf5c66a43
Added to database: 09/14/2026, 08:31:39 UTC
Last enriched: 09/14/2026, 08:31:48 UTC
Last updated: 09/14/2026, 09:27:14 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.