ScreenConnect client file runs hit CISA KEV
How to fix CVE-2026-84869: upgrade ScreenConnect to 26.6.5 or later, then reinstall host clients and update access agents
Contents
CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog today (2026-09-11). ConnectWise disclosed the bug on September 8 and shipped ScreenConnect 26.6.5 the same day. The failure is in the client: during an active Support or Access session, file-transfer actions can land on the Host and run without the Host confirmation operators expect. That includes elevated execution paths. ScreenConnect servers are not in the blast radius.
Cloud instances already run 26.6.5 on the server side. You still need to reinstall host clients and update access agents so the endpoints pick up the client fix. On-prem partners upgrade the server to 26.6.5 or later, then do the same client refresh. Federal KEV due date is 2026-09-14. Forensic triage is marked Yes.
What breaks
ConnectWise rates CVE-2026-84869 Critical, CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Weaknesses: missing authorization (CWE-862) and improper privilege management (CWE-269). Earlier ScreenConnect Client builds for Support and Access sessions processed file-transfer actions through an active remote session without proper authorization or Host confirmation. Under those conditions a Guest-side actor in the session can transfer a file to the Host and execute it, including elevated execution actions.
Impacted product line: ScreenConnect versions prior to 26.6.5. Fixed line: ScreenConnect 26.6.5 and later. NVD published the record 2026-09-08.
Priority on the ConnectWise bulletin is Priority 1 High: either being targeted or at higher risk of being targeted in the wild. Treat the client refresh as an emergency change, not a quiet backlog ticket.
Who is not in scope
- ScreenConnect servers themselves. The advisory is explicit: servers are not impacted. This is a client/session handling bug, not a server RCE.
- Idle boxes with no active remote session. The condition rides an active Support or Access session. It is not "anyone on the internet can drop a binary with zero session."
- Cloud partners who already reinstalled host clients and access agents after the 26.6.5 cloud push. The server is already remediated in cloud; remaining risk is stale clients.
- On-prem installs that cannot reach 26.6.5 yet because they are below 25.4. ConnectWise requires 25.4 or later before the 26.6.5 upgrade path. Those partners still need a plan (upgrade train, license eligibility, or TransferFiles mitigation below), but the 26.6.5 installer is not the first click.
One operator check
On the ScreenConnect instance, open Administration → Overview and read the current version. Anything prior to 26.6.5 is still on the vulnerable train for on-prem. Cloud partners should see 26.6.5 on Overview already; then verify host clients and access agents were actually reinstalled or updated after that push, not just that the server badge moved.
While you wait for a maintenance window, cut the immediate path: Administration → Security → Roles, edit each role, and deselect TransferFiles on every session group that has it. Save. Repeat for each role. ConnectWise calls this temporary mitigation, not a substitute for 26.6.5.
How to fix
Upgrade ScreenConnect to 26.6.5 or later, then refresh every host client and access agent.
- Cloud: server side is already updated. Reinstall host clients and update access agents per ConnectWise docs so endpoints leave the vulnerable client build.
- On-prem: download 26.6.5 from the ScreenConnect download page (valid on-prem license required). Confirm Latest Eligible Version on Administration → Overview before you install. If the license is out of maintenance, renew or upgrade the license first. Automate-integrated on-prem installs pull 26.6.5 through Automate Product Updates when Automate Assurance is active.
- After the server bump: reinstall host clients and update access agents the same way cloud partners must. Patching the server alone does not retire every stale client.
- Interim: strip
TransferFilesfrom roles as above until 26.6.5 is live everywhere that matters.
ConnectWise also tells partners to review users with ScreenConnect access after the patch: remove unused accounts, re-check role grants, and treat unexpected session or transfer history as investigation material. That matches CISA's forensic-triage flag on this KEV entry.
What this is not
This is not an unauthenticated internet worm that pops ScreenConnect servers with no session. It is a client-side authorization failure during an already-active remote session: file transfer and execution without the Host confirmation operators rely on. Do not skip the client refresh because "cloud already says 26.6.5."
References
Continue reading
All posts
Self-managed GitLab: unauth commits API file read hits CISA KEV
How to fix CVE-2026-85706: upgrade GitLab to 19.1.8 / 19.2.6 / 19.3.2

BREAKING: CVE-2026-67276 and MikroTrick can take over MikroTik RouterOS with SSH exposed
How to fix CVE-2026-67276: upgrade RouterOS to 7.24.2, 7.23.4, or 6.49.21

Artifactory anonymous token chain hits CISA KEV
How to fix CVE-2026-42018 / CVE-2026-42016: upgrade self-hosted Artifactory past the anonymous-JWT and token-scope floors (prefer 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20)
