preloader

· · digital-security devops cve msp remote-monitoring connectwise screenconnect cisa-kev vulnerability-management patch-management europe

A ScreenConnect Session Guest Could Run Files on Your Machine Without Asking, and Today Is the Patch Deadline

Source: Daily CyberSecurity

The whole point of a remote support session is that the technician can act on your machine while you watch. CVE-2026-84869 broke that assumption in the other direction: it let the person on the guest side act on the host’s machine while the host had no say in it at all.

A confirmation step that quietly stopped confirming

ScreenConnect, ConnectWise’s remote support and unattended access product, is built around a simple trust boundary: file transfers between guest and host during a live session are supposed to require the host’s explicit approval before anything lands on disk, let alone runs. CVE-2026-84869, tracked as CWE-862 (missing authorization) and CWE-269 (improper privilege management), is a client-side flaw in that approval flow. Under the right conditions, a guest in an active Support or Access session could transfer a file to the host and have it execute without the host confirming anything, including execution paths that carry elevated privileges. ConnectWise rates it Critical, CVSS 9.9. Every ScreenConnect client build before 26.6.5 is affected; ScreenConnect servers themselves are not.

Five days from warning to patch, then straight to active exploitation

ConnectWise first warned customers about an authentication weakness in the file-transfer flow, then shipped the fix, ScreenConnect 26.6.5, five days later on September 8. That gap is short by vendor standards, but it was not short enough. CISA confirmed the flaw was already being exploited in the wild and added it to the Known Exploited Vulnerabilities catalog on September 11, giving US federal civilian agencies until September 14, today, to remediate.

Why this one matters more than the average client-side bug

Remote support tools like ScreenConnect are deliberately positioned with wide reach: one compromised or abused session can touch every endpoint a technician manages. That is precisely the profile that has made ScreenConnect and its predecessors a repeat target, most notably the 2024 authentication bypass that was mass-exploited within days of disclosure to plant ransomware footholds across managed environments. A flaw that lets a guest write and run files on the host without confirmation fits the same pattern: it turns the tool IT teams trust most into the fastest path to every machine behind it. European MSPs and internal IT departments that rely on ScreenConnect for day-to-day support are exactly the population this affects, whether or not any single organisation has been named publicly yet.

What to check today

Confirm every ScreenConnect client in your environment, and every client your MSP manages on your behalf, is running 26.6.5 or later. Reinstall host clients and update access agents rather than assuming an in-place update caught everything, since client-side flaws like this one live in code that gets cached on endpoints. If you cannot confirm your provider has already done this, ask them directly today rather than at the next scheduled check-in.

If you want a European team to audit which remote support and RMM tools your organisation or your vendors are running, confirm they are patched, and tighten session controls so a single compromised support tool never becomes a way into your whole fleet, contact Excello Digital. We help organisations close exactly this kind of exposure before attackers find it first.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!