CVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

Summary

ConnectWise ScreenConnect has an improper privilege management and missing authorization vulnerability. This flaw could allow an attacker to transfer files and execute commands on an active remote session without needing authorization or host confirmation. Affected users are instructed to apply vendor mitigations and follow CISA guidance on prioritizing security updates.

IFF Assessment

FOE

This vulnerability allows unauthorized file transfer and execution, which is detrimental to defenders.

Severity

9.9 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 14, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in ConnectWise ScreenConnect is critical for defenders to address, as it allows for unauthorized remote code execution and file transfer. Prompt patching and adherence to CISA's directives are essential to prevent potential exploitation, especially by ransomware groups.

Read Full Story →