Skip to content
Rush Commerce
Software & Dev3 min read

ScreenConnect CVE-2026-84869: the workaround wasn't the fix

The ScreenConnect file-transfer worm now has a CVE, a CVSS 9.9, a patch in 26.6.5, and a CISA KEV deadline of September 14. Disabling TransferFiles is not enough.

Last week the ScreenConnect file-transfer attack had no CVE and no patch, and ConnectWise's guidance was to turn off TransferFiles and wait. That phase is over. The flaw is now CVE-2026-84869, it carries a CVSS of 9.9, ConnectWise shipped a fix, and CISA added it to the Known Exploited Vulnerabilities catalog on September 11 with a federal remediation deadline of September 14.

What actually happened

The bug is a client-side file-transfer handling condition in ScreenConnect Support and Access sessions. File-transfer actions could be processed through an active remote session without proper authorization or Host confirmation — meaning files land on the Host machine and, under the right conditions, execute there, including through elevated execution actions.

ConnectWise released ScreenConnect 26.6.5 on September 8. Everything before that is affected. The important scoping detail: ScreenConnect servers are not impacted. This is a client-side problem. Clients running pre-26.6.5 builds on on-premises deployments are vulnerable, as are host clients that were never updated or reinstalled per the vendor's guidance.

CISA's catalog entry lists it as added 2026-09-11 with a due date of 2026-09-14, which is the agency's way of saying this is being used against real targets right now. It arrived alongside four other actively exploited flaws in the same batch — two in JFrog Artifactory and two in MikroTik RouterOS — per The Hacker News.

Why this matters for your business

Most small companies do not run ScreenConnect. Their managed service provider does, and the agent is sitting on every workstation in the office right now with the permissions an MSP tool needs. The vendor relationship is the exposure.

That client-side scoping is what makes this ugly. If you patched a server and called it done, you did not fix anything — the vulnerable code is on the endpoints. And the remediation is not a one-step upgrade. Patch to 26.6.5 or later, then reinstall host clients and update access agents. Skipping the second half leaves vulnerable clients in place under a patched version number, which is the exact failure mode that turns a closed ticket into an incident.

If you did the TransferFiles workaround last week, that bought you time. It is not the fix. Go ask your MSP three questions today, in writing: what ScreenConnect version are our agents on, have host clients been reinstalled since the 26.6.5 upgrade, and when was that done. A vendor who cannot answer inside a day is telling you something about how they run their patch process.

And the broader lesson holds past this CVE. Your remote-access tooling is the highest-value target in a small business network — it is designed to reach every machine, with permission. When a vendor publishes an interim mitigation, put a calendar reminder on the real patch, because the mitigation was never the finish line.

Key takeaways

  • The ScreenConnect file-transfer flaw now has a CVE: CVE-2026-84869, CVSS 9.9
  • Files could transfer and execute on the Host through an active session without authorization or Host confirmation
  • ConnectWise shipped the fix in ScreenConnect 26.6.5 on September 8; all earlier versions are affected
  • Servers are not impacted — this is client-side, so patching the server alone fixes nothing
  • CISA added it to KEV on September 11 with a September 14 federal deadline, confirming active exploitation
  • Full remediation is upgrade to 26.6.5, then reinstall host clients and update access agents

Your MSP's remote-access agent runs on every machine you own. That is worth an inventory and a named patch owner, not a trust exercise. We audit the vendor tooling with standing access to your network and document who updates what. Start with your vendor list or see how we scope it.

Sources: CISA Known Exploited Vulnerabilities Catalog, ConnectWise Advisories, The Hacker News.

  • #screenconnect
  • #connectwise
  • #cve-2026-84869
  • #cisa-kev
  • #rmm
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.