PT-2026-88316 · Connectwise · Screenconnect
CVE-2026-84869
·
Published
2026-09-08
·
Updated
2026-09-12
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-84869 (CVSS 9.9): a flaw in the ScreenConnect client lets files be transferred and executed during an active remote session — no authorization or host confirmation required. ScreenConnect servers are not impacted.
ConnectWise patched it five days after their initial warning.
Added to CISA's KEV catalog on September 11.
Update now.
Details: https://t.co/Q3AI0Hl29P
#ConnectWise #ScreenConnect #CVE #CISA #VulnTracker
Exploit
Fix
RCE
Improper Privilege Management
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Screenconnect