The whole point of a remote support session is that the technician can act on your machine while you watch. CVE-2026-84869 broke that assumption in the other direction: it let the person on the guest side act on the host’s machine while the host had no say in it at all.
A confirmation step that quietly stopped confirming
ScreenConnect, ConnectWise’s remote support and unattended access product, is built around a simple trust boundary: file transfers between guest and host during a live session are supposed to require the host’s explicit approval before anything lands on disk, let alone runs. CVE-2026-84869, tracked as CWE-862 (missing authorization) and CWE-269 (improper privilege management), is a client-side flaw in that approval flow. Under the right conditions, a guest in an active Support or Access session could transfer a file to the host and have it execute without the host confirming anything, including execution paths that carry elevated privileges. ConnectWise rates it Critical, CVSS 9.9. Every ScreenConnect client build before 26.6.5 is affected; ScreenConnect servers themselves are not.
Five days from warning to patch, then straight to active exploitation
ConnectWise first warned customers about an authentication weakness in the file-transfer flow, then shipped the fix, ScreenConnect 26.6.5, five days later on September 8. That gap is short by vendor standards, but it was not short enough. CISA confirmed the flaw was already being exploited in the wild and added it to the Known Exploited Vulnerabilities catalog on September 11, giving US federal civilian agencies until September 14, today, to remediate.
Why this one matters more than the average client-side bug
Remote support tools like ScreenConnect are deliberately positioned with wide reach: one compromised or abused session can touch every endpoint a technician manages. That is precisely the profile that has made ScreenConnect and its predecessors a repeat target, most notably the 2024 authentication bypass that was mass-exploited within days of disclosure to plant ransomware footholds across managed environments. A flaw that lets a guest write and run files on the host without confirmation fits the same pattern: it turns the tool IT teams trust most into the fastest path to every machine behind it. European MSPs and internal IT departments that rely on ScreenConnect for day-to-day support are exactly the population this affects, whether or not any single organisation has been named publicly yet.
What to check today
Confirm every ScreenConnect client in your environment, and every client your MSP manages on your behalf, is running 26.6.5 or later. Reinstall host clients and update access agents rather than assuming an in-place update caught everything, since client-side flaws like this one live in code that gets cached on endpoints. If you cannot confirm your provider has already done this, ask them directly today rather than at the next scheduled check-in.
If you want a European team to audit which remote support and RMM tools your organisation or your vendors are running, confirm they are patched, and tighten session controls so a single compromised support tool never becomes a way into your whole fleet, contact Excello Digital. We help organisations close exactly this kind of exposure before attackers find it first.
