Critical 9.9 Actively Exploited

ScreenConnect client RCE actively exploited (CVE-2026-84869)

CVE-2026-84869

By Yazoul AI · automated

CVE-2026-84869: ScreenConnect client file transfer and execution bypass in active sessions, CVSS 9.9, CISA KEV. Update ConnectWise ScreenConnect to 25.1.3 or later now.

Affected: Connectwise Screenconnect

Actively exploited in the wild - CVE-2026-84869 is a critical unauthorized file transfer and execution flaw in the ConnectWise ScreenConnect client that lets an attacker push and run files through an active remote session without Host confirmation or operator authorization. ScreenConnect servers are not affected; patched clients ship in the 25.1.3 release line.

Overview

CVE-2026-84869 lives in the ScreenConnect client on the technician-attached or attended endpoint, not in the on-premises or cloud ScreenConnect server. Under specific session conditions - most often an established remote control session where the Host has already granted screen control - the client fails to enforce the expected authorization path for file transfer and subsequent execution. An attacker positioned on the relay path or abusing a compromised technician session can drop a file onto the endpoint and trigger it without the Host ever being prompted for confirmation.

The CVSS score is 9.9 (NETWORK / LOW complexity / LOW privileges / NO user interaction). The low privileges and zero-interaction profile is what makes this severe: the victim does not need to click anything to accept a file, because the normal Host confirmation prompt is what the flaw bypasses.

CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog based on confirmed in-the-wild activity. The EPSS score sits at 0.4 percent, meaning mass opportunistic scanning is unlikely - this is a targeted technique, not a worm. Do not let the low EPSS lull you into delay; KEV status means real campaigns are already using it.

Impact

  • Arbitrary file write into the session endpoint’s filesystem with the client’s privilege level.
  • Execution of the transferred file inside the active session, bypassing the Host confirmation step.
  • Effective remote code execution against the endpoint when combined with a signed or trusted binary target.
  • Lateral risk to managed service providers, where a single compromised technician workstation can reach many customer endpoints.

Endpoints with the ScreenConnect client installed but not currently in a session are not exposed. The window is an active remote session, so unattended endpoints sitting idle are lower risk than those being actively supported.

Remediation and mitigation

  1. Update the ScreenConnect client to the fixed release as published in the ConnectWise advisory (25.1.3 line). Note that the server is not the fix surface here - updating only the server leaves clients exposed.
  2. Use the ScreenConnect administrative console to push the client update to every managed endpoint, including unattended machines.
  3. Rotate technician credentials and session tokens if you cannot rule out a compromised operator account, since the flaw rides on an authorized session.
  4. Restrict file transfer and remote execution permissions in ScreenConnect roles until all clients report the patched version.
  5. Monitor session logs for unexpected file transfer events paired with process creation on the endpoint; EDR telemetry from ScreenConnect.ClientService.exe child processes is the highest-signal source.
  6. Invalidate any session that transferred a file the Host did not explicitly approve and triage the endpoint.

If this incident touched customer data, breach reports are available at breach reports and ongoing coverage at security news.

Security Insight

ScreenConnect has become one of the most abused remote monitoring and management platforms in ransomware intrusions because it is legitimately signed, legitimately installed, and reaches the exact endpoints attackers want. CVE-2026-84869 removes even the thin friction of a Host confirmation prompt, which means the detection window shrinks to endpoint telemetry rather than any user-visible signal. The vendor’s split between a “server not impacted, client impacted” fix also creates a predictable patch gap, since many organizations remediate the console and assume the fleet is done. Expect this CVE to appear in initial access broker toolkits before the client patch cycle completes.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Related Advisories

Other Connectwise Screenconnect Vulnerabilities

View all Connectwise Screenconnect vulnerabilities →

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.