Security Bulletin logo with a close up of a wolf in the background.
Security Bulletin logo with a close up of a wolf in the background.

CVE-2026-84869: ConnectWise ScreenConnect Client Vulnerability Critical Remote Session File Transfer Exploitation Risk

Learn about CVE-2026-84869, an actively exploited ConnectWise ScreenConnect vulnerability that could allow unauthorised file transfers, remote code execution, and endpoint compromise through active sessions.
Security Bulletin logo with a close up of a wolf in the background.
6 min read

Threat Summary

A critical security weakness (CVE-2026-84869) has been identified in the ConnectWise ScreenConnect client (prior to version 26.6.5), where missing authorisation controls and improper privilege management allow file transfers and execution through active remote sessions without host confirmation.

While the vulnerability is restricted to the client and session handling components (the server itself is not directly affected), attackers can exploit this flaw to bypass file transfer restrictions, upload or run malicious payloads, and potentially gain control over endpoints using ScreenConnect for remote management. The vulnerability is classified as CVSS 3.1 score 9.9 (Critical) and labeled “Important/Priority 1” by ConnectWise.

CVE-2026-84869 was added to the CISA KEV catalog on September 11, 2026, with remediation required by September 14, 2026. At the time of writing, no public proof of concept is available. Threat actors are actively exploiting this vulnerability to compromise environments.

Arctic Wolf has active detection coverage for CVE-2026-84869 exploitation, and customers using the AWN Agent and/or benefit from multi-stage endpoint detection. However, Arctic Wolf strongly recommends upgrading ScreenConnect to version 26.6.5 or later as the primary remediation for this vulnerability.

Recommendations for CVE-2026-84869

Immediate Actions:

Upgrade all ConnectWise ScreenConnect client installations to version 26.6.5 or later:

  • On-premises instances must be running version 25.4+ or later to upgrade to 26.6.5.
  • Cloud deployments are auto-updated, but require a host client and agent refresh/removal after the upgrade.

Enforce a credential hygiene campaign:

  • Reset administrator and privileged user passwords, enable multi-factor authentication (MFA), and validate all user and agent accounts.

Ongoing/Preventive Measures:

  • Restrict ScreenConnect web interface and relay access to trusted IPs using firewall rules or reverse proxies. Deploy ScreenConnect behind VPNs or internal networks where possible.
  • Configure SSL/TLS, remove unused extensions, apply the principle of least privilege to user accounts.
  • Conduct post-upgrade audits and maintain centralised logs for all file transfer and session actions.

Temporary Workarounds

If immediate patching to 26.6.5+ is not possible:

  • Remove/disable the TransferFiles (or legacy TransferFilesInSession) permission from all roles to block in-session file transfer and remote execute features.
  • Enforce session policies requiring explicit Host confirmation/consent where available and restrict elevated session modes.
  • Consider endpoint application control to prevent execution from user-writable paths and to constrain child processes spawned by ScreenConnect client binaries.
  • Limitations: These workarounds mitigate risk but do not eliminate the underlying vulnerability—full software upgrade is required for complete remediation.

References

Share this post: