CISA Warns: Critical ConnectWise ScreenConnect Flaw Actively Exploited In The Wild
A critical-severity vulnerability in **ConnectWise ScreenConnect** is now under active exploitation, prompting an urgent alert from the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)**. The flaw, **CVE-2026-84869**, allows attackers with basic privileges to transfer and execute files without authorization, posing significant risks to organizations relying on the remote access platform.

**CISA** has issued a stark warning regarding a critical-severity vulnerability in **ConnectWise ScreenConnect**, confirming its active exploitation by threat actors. The agency has added the flaw to its catalog of actively exploited vulnerabilities, mandating U.S. federal agencies to patch their systems within three days.
### The Vulnerability: CVE-2026-84869
The vulnerability, tracked as **CVE-2026-84869**, is an improper privilege management and missing authorization flaw affecting **ScreenConnect** clients. It enables threat actors with basic privileges to transfer or execute files during active remote sessions without requiring host confirmation or additional user interaction. This low-complexity attack vector presents a significant risk for organizations utilizing the platform for remote support and system maintenance.
**ConnectWise** initially provided temporary mitigation measures on September 7, advising security teams to disable 'TransferFiles' permissions to block potential attacks. The vulnerability has since been patched in **ScreenConnect** 26.6.5 and later versions.
### Widespread Exposure and Active Exploitation
**CISA** highlighted that these types of vulnerabilities are frequent attack vectors for malicious cyber actors, posing substantial risks to the federal enterprise and beyond. This is not the first time **ScreenConnect** has been in the spotlight for security issues.
Since 2024, **CISA** has flagged four **ScreenConnect** security issues as actively exploited, with two of these having been leveraged in ransomware attacks.
Internet threat watchdog **Shadowserver** reports that over 1,000 **ScreenConnect** instances remain unpatched and exposed online, with the majority located in North America (758) and Europe (180).

*Vulnerable ScreenConnect instances (Shadowserver)*
### A History of Targeted Exploitation
**ScreenConnect** vulnerabilities are frequently targeted by both financially motivated and state-backed hacking groups. For instance, the North Korean-backed **Kimsuky** hacking group and several ransomware gangs exploited another **ScreenConnect** flaw, **CVE-2024-1709**, in 2024.
Last year, **ConnectWise** also undertook a rotation of digital code-signing certificates following a breach linked to suspected state-sponsored hackers. These attackers exploited a **ViewState** flaw (**CVE-2025-3935**) to gain access to cloud-based instances of a limited number of customers through code injection attacks.
More recently, in March, **ConnectWise** addressed **CVE-2026-3564**, a cryptographic signature verification vulnerability that could allow attackers to hijack unpatched **ScreenConnect** servers.
**ConnectWise** provides services to over 100,000 IT providers globally, with many Managed Service Providers (**MSPs**) and IT teams relying on its **ScreenConnect** remote access platform for critical functions like troubleshooting, patching, and system maintenance. The ongoing exploitation of these vulnerabilities underscores the critical need for immediate patching and robust security practices.