ScreenConnect CVE-2026-84869 Hit CISA’s KEV — Patch Clients to 26.6.5
If you run a Staten Island shop, a Midtown law office, or a Bay Ridge medical practice that leans on remote support, today’s clock matters. ScreenConnect CVE-2026-84869 — a client-side flaw rated CVSS 9.9 — landed on CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 11, 2026, with a federal remediation due date of September 14, 2026. That is not a “schedule it next month” item for anyone who still has technicians jumping into live sessions.
ConnectWise’s September 8 bulletin is blunt about the shape of the risk: under certain circumstances, files can be transferred and executed through an active remote session without authorization or Host confirmation. ScreenConnect servers are not impacted. The fix is ScreenConnect 26.6.5+, plus reinstalling host clients and updating access agents after you upgrade. If you cannot patch in the same day, the temporary mitigation is to deselect the TransferFiles permission on every role.
This post is a practical checklist for NYC SMBs and the MSPs who support them — not a walkthrough for attackers. We cite ConnectWise, CISA’s KEV entry, Huntress’s field reporting, and secondary coverage from SecurityWeek and The Hacker News. No invented percentages. No exploit recipes.
What CVE-2026-84869 actually is
Per ConnectWise’s Trust bulletin dated September 8, 2026, the issue is tracked as CVE-2026-84869 with two related weakness classes: CWE-862 (Missing Authorization) and CWE-269 (Improper Privilege Management). The published base score is 9.9 on CVSS 3.1, with the vector ConnectWise lists as CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.
ConnectWise rates severity as Important and priority as 1 – High — language they reserve for issues that are being targeted or that carry higher risk of being targeted in the wild, with a recommendation to treat updates as emergency changes (within days).
The summary that matters for operators: the condition sits in the ScreenConnect client. It may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ConnectWise is explicit that ScreenConnect servers are not impacted. Versions prior to 26.6.5 are listed as affected. The 26.6.5 patch strengthens client and session handling for file-transfer and file-execution actions.
That “client, not server” distinction is easy to miss in a Friday triage pile. Upgrading the appliance or cloud instance is necessary — and ConnectWise says cloud instances were moved onto the fixed line — but the bulletin also tells partners to reinstall host clients and update access agents after the upgrade. For on-premises partners, the documented upgrade path requires running 25.4 or later before moving to 26.6.5, and license eligibility still has to check out on Administration → Overview.
Why CISA put it on the KEV — and why today is the due date
CISA’s KEV catalog entry for CVE-2026-84869 (pulled from the public KEV JSON feed) lists:
- Vendor / product: ConnectWise / ScreenConnect
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Date added: 2026-09-11
- Due date: 2026-09-14
- CWEs: CWE-269, CWE-862
- Forensic triage required (BOD 26-04): Yes
- Known ransomware campaign use: Unknown
The short description in the catalog matches the vendor story: improper privilege management and missing authorization that may allow file transfer and execution through an active remote session without authorization or host confirmation. Required action language points at vendor mitigations and BOD 26-04 guidance — including forensic triage expectations for assets that were exposed.
Federal Civilian Executive Branch agencies live under that due date. Private NYC firms are not BOD-bound the same way, but the practical lesson is the same: when CISA stamps a remote-support client bug as known-exploited with a three-day clock, waiting for the next quiet change window is a bet against observed abuse.
The Hacker News (September 12) and SecurityWeek (September 14) both reported the KEV addition and tied the exploitation narrative to Huntress’s earlier field work. Use them as secondary confirmation; treat ConnectWise and CISA as primary.
What Huntress saw in the wild
Huntress published “Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity,” then updated it after the ConnectWise patch. The operational picture, in their words and timeline:
- In late August 2026, their SOC issued three critical incident reports across unrelated organizations for malicious ScreenConnect installs and unexpected process execution.
- Rogue ScreenConnect clients repeatedly spawned
wscript.exeto run a staged VBScript set commonly referred to in the write-up as1.vbsthrough4.vbs. - Initial access in the documented cases leaned on social engineering (for example Quick Assist abuse, a phishing-delivered MSI, and a fake Geek Squad refund lure) — classic paths into small businesses that already trust remote helpers.
- The part that turns this into an MSP problem rather than a one-off scam: Huntress described modified ScreenConnect clients that could propagate the same VBScript chain to newly connected ScreenConnect endpoints, creating worm-like spread when a clean host connects to an infected client.
- After the September 8 patch, Huntress’s update restated CVE-2026-84869 at CVSS 9.9, confirmed servers are not impacted, and urged organizations to move to 26.6.5. They also noted that, under certain circumstances, files could be transferred to and executed on the Host client system, including through elevated execution actions.
Huntress recommended reimaging heavily affected hosts from known-good media and watching ScreenConnect audit logs for suspicious RunFiles / RanFiles activity (especially script execution attributed from the Guest side). That is detection hygiene — not a how-to for anyone on the wrong side of the keyboard. If your Staten Island helpdesk jumped into a suspicious session last month, pull those audit rows before you declare the incident closed.
SecurityWeek summarized the same arc: exploitation observed since about August 20 per Huntress, social-engineering installs of rogue clients, propagation toward connected targets, vendor fix in 26.6.5, temporary mitigation by disabling TransferFiles, and CISA’s Friday KEV add under BOD 26-04.
What to do this morning (MSP / NYC SMB checklist)
1. Confirm version and eligibility
On cloud instances, ConnectWise states the server side was updated automatically — still verify Administration → Overview and confirm you are on 26.6.5+. On-premises partners: download and apply 26.6.5 from the licensed download path, confirm you are already on 25.4+ for the supported upgrade path, and check “Latest Eligible Version” if your license is near renewal. Automate on-prem partners with ScreenConnect integration can pull 26.6.5 through Automate Product Updates when Assurance is active, per the bulletin.
2. Reinstall host clients and refresh access agents
Do not stop at the server build number. ConnectWise’s remediation language for both cloud and on-prem tells you to reinstall host clients and update access agents after upgrading. That is the step that tends to slip when a Midtown account manager only screenshots the Overview page.
3. If you cannot patch yet — temporary TransferFiles mitigation
ConnectWise’s temporary mitigation (not a substitute for the patch):
- Go to Administration → Security → Roles.
- Edit each role; review every session group with permissions assigned.
- Deselect TransferFiles (previously named TransferFilesInSession on legacy builds) if it is selected.
- Save, then repeat for every role.
Document who approved the temporary restriction, and put the real upgrade on today’s change calendar — not next quarter’s.
4. Hunt for odd sessions and guest-side file runs
Pull ScreenConnect audit history for unexpected guest-originated file run events, unfamiliar client IDs, and sessions that do not match ticket work. Huntress’s public guidance is to treat suspicious script execution from Guest in those logs as a reason to rebuild the device, not to “clean it in place” and hope. Pair that with your EDR timeline for wscript.exe children under ScreenConnect processes.
5. Assume social engineering is still the front door
The Huntress cases did not start with a magical WAN packet. They started with people being talked into Quick Assist, a downloaded MSI, or a refund-form lure. Remind front-desk staff in Bay Ridge and warehouse leads in Brooklyn: nobody legitimate needs them to install a surprise remote tool from a cold call. Your approved remote path is the one your MSP already provisioned.
6. After the patch — lock the room back down
ConnectWise’s post-patch FAQ still expects the boring controls: review who has ScreenConnect access, remove unrecognized users, tighten roles, rotate passwords, and keep MFA on. A patched client with a shared “support” login is still a bad day waiting to happen.
How MicroSky thinks about this for managed clients
Remote support is how we keep a five-person accounting firm on South Avenue productive without camping in their conference room. It is also a high-value trust channel. When the vendor and CISA both say a client-side session flaw is known-exploited, we treat host-client inventory as a first-class asset list — same urgency we give firewall KEVs, not “nice-to-have agent hygiene.”
For clients we manage, the work looks like: confirm 26.6.5+ everywhere it applies, push client/agent refresh, temporarily clamp TransferFiles only where a change freeze truly blocks the upgrade, then review session audit and EDR for the Huntress-style patterns. For clients who self-manage ScreenConnect on-prem, the same checklist applies — and if your license is out of maintenance, ConnectWise’s bulletin is clear that you may need to fix licensing before you can land on the supported build.
We are not going to invent a “percentage of NYC firms already hit” number. The sourced fact is simpler: Huntress documented multiple unrelated incidents, ConnectWise shipped an emergency-priority client fix, and CISA gave federal teams until today to remediate. That is enough signal to act.
Bottom line
Patch ScreenConnect environments to 26.6.5+, refresh host clients and access agents, use the TransferFiles deselect only as a bridge, and review session logs if anyone connected to unfamiliar clients in August. The federal clock on CVE-2026-84869 lands on September 14, 2026 — the same day many NYC offices are already juggling Monday ticket queues. Make the remote-support stack part of that queue, not the thing you skip because “the server looks fine.”
Need a second set of eyes on your ScreenConnect client inventory or KEV triage? Call MicroSky Managed Services at (718) 672-2177 or visit https://microskyms.com.

