A Critical Vulnerability in ScreenConnect is Being Actively Exploited by Attackers
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in the popular remote access platform ScreenConnect to its list of actively exploited flaws. This means that attackers are already using the flaw to launch attacks on vulnerable systems, putting many organizations at risk.
ScreenConnect is a widely used platform for troubleshooting, patching, and system maintenance, with over 100,000 IT providers worldwide relying on it. The vulnerability in question, tracked as CVE-2026-84869, allows attackers with basic privileges to transfer or execute files without authorization, even if they don’t require user interaction. This can be particularly problematic for organizations that use ScreenConnect to provide remote access to their systems.
CISA has ordered US federal agencies to secure their systems against ongoing attacks within three days and has shared temporary mitigation measures with the public. These measures include disabling TransferFiles permissions, which can block potential attacks. However, it’s essential to note that these measures are only temporary and should not be relied upon as a long-term solution.
The vulnerability in ScreenConnect is just the latest in a series of critical security issues affecting the platform. Since 2024, CISA has flagged four ScreenConnect security issues as actively exploited, including two that were used in ransomware attacks. The Internet threat watchdog Shadowserver now tracks over 1,000 ScreenConnect instances still unpatched and exposed to attacks online, with most located in North America and Europe.
ScreenConnect vulnerabilities are often targeted by financially motivated and state-backed hacking groups alike. In the past, hackers have exploited similar flaws to gain access to sensitive systems and disrupt critical infrastructure. It’s essential for organizations using ScreenConnect to take immediate action to patch their systems and implement additional security measures to prevent attacks.
For IT teams relying on ScreenConnect, it’s crucial to prioritize patching and updating their instances as soon as possible. This includes not only installing the latest version of ScreenConnect but also ensuring that all associated systems and software are up-to-date. Additionally, organizations should consider implementing extra security controls, such as monitoring for suspicious activity and implementing robust access controls.
Ultimately, the active exploitation of this critical vulnerability in ScreenConnect serves as a stark reminder of the importance of prioritizing cybersecurity and staying vigilant against emerging threats. By taking proactive steps to secure their systems and staying informed about potential vulnerabilities, organizations can better protect themselves against cyber attacks and minimize the risk of data breaches.
Source: Bleeping Computer — 2026-09-16