A critical security vulnerability in ConnectWise’s ScreenConnect remote access platform is being actively exploited by attackers, putting thousands of organizations and their clients at risk. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its catalog of actively exploited vulnerabilities and ordered federal agencies to patch it within three days.
The vulnerability, identified as CVE-2026-84869, allows threat actors with basic privileges to transfer or execute files on compromised systems without authorization. This can happen in low-complexity attacks that don’t require user interaction, making it a serious concern for IT teams and their clients. ConnectWise shared temporary mitigation measures, advising security teams to disable TransferFiles permissions to block potential attacks.
The ScreenConnect platform is widely used by over 100,000 IT providers worldwide, including managed service providers (MSPs) and IT teams, for tasks such as troubleshooting, patching, and system maintenance. However, this has also made it a prime target for attackers, with several groups exploiting its vulnerabilities in recent years. In fact, CISA has flagged four ScreenConnect security issues since 2024 as actively exploited, two of which were used in ransomware attacks.
The Shadowserver threat intelligence group estimates that over 1,000 ScreenConnect instances remain unpatched and exposed to attacks online, with most located in North America (758) and Europe (180). This highlights the urgent need for organizations using ScreenConnect to patch their systems as soon as possible. The fact that state-backed hacking groups like Kimsuky have exploited these vulnerabilities in the past only adds to the gravity of this situation.
The exploitation of this vulnerability is not an isolated incident. In recent years, ConnectWise has faced several security incidents, including a breach by suspected state-sponsored hackers who exploited a ViewState flaw (CVE-2025-3935) and accessed cloud-based instances of some customers. This latest development serves as a reminder that the security posture of remote access platforms like ScreenConnect is critical to preventing cyber attacks.
For IT teams and their clients using ScreenConnect, it’s essential to prioritize patching their systems immediately. This includes applying the latest updates (ScreenConnect 26.6.5 or later) and ensuring that TransferFiles permissions are disabled as a temporary mitigation measure. It’s also crucial for organizations to regularly review and update their security protocols to stay ahead of emerging threats. By taking proactive steps, they can minimize the risk of falling victim to these attacks and protect their sensitive data from unauthorized access.
Source: Bleeping Computer — 2026-09-16