AI description
CVE-2026-84869 describes a vulnerability found within the ScreenConnect client. This flaw permits the unauthorized transfer and execution of files during an active remote session, bypassing typical authorization or host confirmation processes. It is important to note that this condition specifically affects the ScreenConnect client and does not impact ScreenConnect servers. The vulnerability is associated with improper privilege management and missing authorization.
- Description
- A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
- Source
- 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
- NVD status
- Analyzed
- Products
- screenconnect
CVSS 3.1
- Type
- Secondary
- Base score
- 9.9
- Impact score
- 6
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Exploit added on
- Sep 11, 2026
- Exploit action due
- Sep 14, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
- CWE-269
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
9
🚨 CRITICAL: CVE-2026-84869 (CVSS 9.9) ScreenConnect client flaw allows unauthorized file transfer & execution during active remote sessions. Servers unaffected. Impact: Remote code execution #CVE #PatchNow #ThreatIntel https://t.co/yz9hw0ZcyQ
@DFIR_Lab
12 Sept 2026
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに3件と1件の脆弱性を追加。 - JFrog Artifactory: CVE-2026-42016, CVE-2026-42018 - ConnectWise ScreenConnect: CVE-2026-84869 - GitLab: CVE-2026-85706
@__kokumoto
12 Sept 2026
515 Impressions
1 Retweet
2 Likes
0 Bookmarks
1 Reply
0 Quotes
🛡️We added JFrog Artifactory vulnerabilities CVE-2026-42016 & CVE-2026-42018 and ConnectWise ScreenConnect vulnerability CVE-2026-84869 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSe
@CISACyber
11 Sept 2026
4490 Impressions
4 Retweets
7 Likes
1 Bookmark
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:*",
"matchCriteriaId": "270783CF-B4ED-4608-A583-A9F7B80DC877",
"versionEndExcluding": "26.6.5.9742",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]