Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

ConnectWise ScreenConnect bug exploited in the wild, CISA says

CVE-2026-84869 is a critical (CVSS 9.9) privilege management flaw in ConnectWise ScreenConnect that allows attackers with basic privileges to transfer and execute arbitrary files without authorization via an active remote session. The vulnerability affects ScreenConnect versions prior to 26.6.5.9742, and a patch is available in version 26.6.5.9742. If immediate patching is not possible, administrators should segregate instances, disable TransferFiles permissions, and monitor for exploitation attempts.
Read Full Article →

Vulnerability Management , Patch/Configuration Management ConnectWise ScreenConnect bug exploited in the wild, CISA says September 16, 2026 Share By Steve Zurier (Adobe Stock) The Cybersecurity and Infrastructure Security Agency (CISA) confirmed that a critical ConnectWise ScreenConnect bug was exploited in the wild. In adding the CVSS 9.9 flaw to its known exploited vulnerabilities (KEV) catalog on Sept. 11, CISA said CVE-2026-84869 was an improper privilege management and missing authorization bug that could let attackers "transfer and execute files via an active remote session without authorization or host confirmation." CISA has added four ScreenConnect flaws to the KEV since 2024, two of which were exploited by ransomware groups. ConnectWise released a patch for this most recent flaw on Sept. 8. Related reading: ScreenConnect abused to deploy AsyncRAT in widespread campaign Trojanized ConnectWise ScreenConnect installers deployed in tax-themed malvertising campaign CISA adds ConnectWise, Microsoft flaws to KEV catalog Security pros said given the compressed timeline between disclosure, exploitation, and ransomware attacks today, it’s only a matter of time before this could become yet another ransomware case. “The ScreenConnect vulnerability lets attackers with basic privileges transfer and execute arbitrary files without authorization or user interaction,” said Shane Barney, chief information security officer at Keeper Security. “That's a direct path to ransomware deployment. The CVSS 9.9 score was assigned because the combination of low complexity, no user interaction and unauthenticated file execution compresses the window between discovery and ransomware weaponization into weeks, not months.” Barney added that ransomware gangs actively monitor the KEV catalog, and once a flaw lands there, the patch window becomes exponentially smaller. Barney said for managed service providers (MSPs), the risk compounds because a compromised instance doesn't just threaten one organization: it threatens the entire downstream chain of clients relying on that MSP for access. “Organizations need to prioritize this patch above the standard quarterly or monthly rhythm most operate from,” said Barney. “If immediate patching is not possible, segregate ScreenConnect instances from sensitive network segments, disable TransferFiles permissions as a temporary measure and monitor for any exploitation attempts. Organizations with unpatched instances exposed to the internet are at elevated risk.” John Strand, owner at Black Hills Information Security, said there are two important points to take from this flaw: First, the amount of time between vulnerability disclosure and active exploitation has gotten ridiculously short. Organizations simply don’t have the luxury of spending weeks testing patches before rolling them into production. Strand said ScreenConnect customers shoul patch right away. “Don’t wait, get it patched,” said Strand. The second issue Strand noted was the broader shift from on-prem technologies to cloud-based SaaS. Strand said he’s still shocked at how slowly many organizations are making that transition, especially for products that already have mature SaaS offerings. “There have always been legitimate reasons for keeping certain technologies on-prem, but some of those reasons are starting to disappear pretty quickly in the face of the attack vectors we’re seeing today,” said Strand. “At some point, organizations have to weigh the risks of moving to the cloud against the growing security burden of maintaining and patching these systems themselves.” Andrew Obadiaru, vice president and CISO at Cobalt, explained that ScreenConnect has been a recurring target for both ransomware crews and state-backed groups since 2024, and that's not really about ConnectWise's code quality: it’s that to an attacker, ScreenConnect represents a pre-established, trusted channel into thousands of environments that IT teams already rely on daily. “Once you can transfer or execute files inside an active session without authorization, you're not breaking in, you're riding in on credentials the system already trusts,” said Obadiaru. “That's the pattern defenders need to internalize. Attackers increasingly go after the tools that sit at the center of trusted relationships between vendors, MSPs, and their customers, because compromising one instance can cascade across every downstream client it touches.” Steve Zurier Steve Zurier has been a freelance writer and editor for SC Media since 2012. Now, Zurier writes daily news stories and edits SC Media’s Perspectives columns. A long-time member of the tech press, Zurier lives in Columbia, MD. During off-hours, Steve moonlights as an upright bassist for jazz and klezmer bands around the Baltimore/DC area. Related Vulnerability Management Nintendo patches critical Nintendo Switch vulnerability SC Staff September 15, 2026 The vulnerability, identified as CVE-2026-82079, affects Switch systems running firmware versions prior to 23.0.0. Vulnerability Management Logitech Options+ vulnerability allows SYSTEM-level privilege escalation SC Staff September 15, 2026 The vulnerability was found in the software's updater service, which runs with extensive operating system access. Vulnerability Management Homebrew 7.0.0 released with built-in vulnerability scanner and improved security SC Staff September 15, 2026 Homebrew, widely used on macOS, is frequently targeted by threat actors to distribute info-stealer malware. Related Events Cybercast State of Vulnerability Management On-Demand Event Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article