Critical ScreenConnect Flaw Actively Exploited in Attacks
CISA added the critical ConnectWise ScreenConnect vulnerability CVE-2026-84869 to its actively exploited catalog and gave US federal agencies three days to patch it. The flaw, involving privilege management and missing authorization, allows file transfer and execution in active remote sessions without host confirmation; the patch is in ScreenConnect 26.6.5.
- Vulnerability CVE-2026-84869 fixed in ScreenConnect 26.6.5 and later
- CISA gave US federal agencies three days to remediate
- Shadowserver tracks over 1,000 unpatched ScreenConnect instances
- 758 vulnerable instances in North America, 180 in Europe
Read next
Security