{"type":"bundle","id":"bundle--5defee6a-3c4c-5a8f-a4df-4a46d74f3259","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--6427bffc-882d-5662-a1c0-bda41de721e6","created":"2026-09-20T18:52:57.433Z","modified":"2026-09-20T18:52:57.433Z","name":"ScreenConnect guest-to-host file execution (CISA KEV)","description":"ConnectWise ScreenConnect clients before 26.6.5 can, under certain conditions, transfer and execute files through an active remote session without Host confirmation. CISA added CVE-2026-84869 to KEV. Upgrade to 26.6.5 or later and refresh Host clients / access agents.","aliases":["CVE-2026-84869","ScreenConnect guest-to-host file execution"],"first_seen":"2026-09-08T00:00:00.000Z","last_seen":"2026-09-11T20:41:45.549Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"CISA Known Exploited Vulnerabilities Catalog","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869"},{"source_name":"NVD CVE-2026-84869","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84869"},{"source_name":"CVE Record CVE-2026-84869","url":"https://www.cve.org/CVERecord?id=CVE-2026-84869"},{"source_name":"Huntress ScreenConnect rogue installations write-up","url":"https://www.huntress.com/blog/rogue-screenconnect-installations"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-84869-screenconnect-client-file-transfer-execution-kev"}]}]}