{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-8F3BA860",
  "slug": "cve-2026-84869-screenconnect-client-file-transfer-execution-kev",
  "title": "ScreenConnect guest-to-host file execution (CISA KEV)",
  "aliases": [
    "CVE-2026-84869",
    "ScreenConnect guest-to-host file execution"
  ],
  "summary": "ConnectWise ScreenConnect clients before 26.6.5 can, under certain conditions, transfer and execute files through an active remote session without Host confirmation. CISA added CVE-2026-84869 to KEV. Upgrade to 26.6.5 or later and refresh Host clients / access agents.",
  "status": "published",
  "severity": "critical",
  "confidence": "high",
  "uncertainty": "Exact session preconditions vary by client build; follow ConnectWise for Host client reinstall requirements beyond the server package bump.",
  "firstObservedAt": "2026-09-08T00:00:00.000Z",
  "lastObservedAt": "2026-09-11T20:41:45.549Z",
  "publishedAt": "2026-09-20T18:52:57.433Z",
  "reviewedAt": "2026-09-20T18:52:44.956Z",
  "expiresAt": "2026-09-11T20:41:45.549Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "cisa-kev",
      "label": "CISA Known Exploited Vulnerabilities Catalog",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869",
      "sourceType": "government",
      "observedAt": "2026-09-11T20:41:45.549Z"
    },
    {
      "id": "nvd",
      "label": "NVD CVE-2026-84869",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84869",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-11T20:41:45.549Z"
    },
    {
      "id": "cveorg",
      "label": "CVE Record CVE-2026-84869",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84869",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-11T20:41:45.549Z"
    },
    {
      "id": "huntress",
      "label": "Huntress ScreenConnect rogue installations write-up",
      "url": "https://www.huntress.com/blog/rogue-screenconnect-installations",
      "sourceType": "research",
      "observedAt": "2026-09-11T20:41:45.549Z"
    },
    {
      "id": "hol-blog",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-84869-screenconnect-client-file-transfer-execution-kev",
      "sourceType": "other_primary",
      "observedAt": "2026-09-11T20:41:45.549Z"
    }
  ],
  "artifacts": [
    {
      "id": "screenconnect",
      "artifactClass": "package",
      "ecosystem": "connectwise",
      "name": "ScreenConnect",
      "version": "<26.6.5",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-09-08T00:00:00.000Z",
      "eventType": "disclosure",
      "summary": "CVE-2026-84869 disclosed for ScreenConnect client guest-to-host file execution.",
      "sourceIds": [
        "nvd",
        "cveorg"
      ]
    },
    {
      "id": "kev",
      "occurredAt": "2026-09-11T00:00:00.000Z",
      "eventType": "other",
      "summary": "CISA listed CVE-2026-84869 in the Known Exploited Vulnerabilities catalog.",
      "sourceIds": [
        "cisa-kev"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-09-11T20:41:45.549Z",
      "eventType": "other",
      "summary": "HOL Guard published operator blog coverage for CVE-2026-84869.",
      "sourceIds": [
        "hol-blog"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "ScreenConnect servers are not impacted per vendor; the client path is in scope.",
    "CISA KEV listing confirms known exploitation interest; this campaign does not invent exploit details beyond public advisories.",
    "HOL blog coverage is operator guidance, not a substitute for the vendor bulletin."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-84869-screenconnect-client-file-transfer-execution-kev/corrections"
}
