CVE-2026-84869
CRITICAL · 9.9 KEV EPSS 0.7%KEV-listed, CISA active exploitation warning, vendor patch released, defenders triaging urgently.
What: ConnectWise ScreenConnect client vulnerability (CVSS 9.9) allowing unauthorized file transfer and execution during remote sessions without host confirmation.
Why it matters: KEV-listed as of 2026-09-11 with CISA-mandated remediation deadline of 2026-09-14. ConnectWise released patch 26.6.5 on 2026-09-08. CISA warns of active exploitation. High severity and rapid official response signal real-world risk.
Where it's seen: Widespread social chatter across Bluesky; CISA advisory; vendor patch released same day as CVE publication; trending on vulnerability monitoring platforms; no public PoC mentioned but active exploitation confirmed by CISA.
RISK: CRITICAL — KEV-listed, CVSS 9.9, CISA confirms active exploitation, 14-day remediation deadline.
Description
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High