## Overview
ConnectWise ScreenConnect has a critical vulnerability identified as CVE-2026-84869. This flaw allows files to be transferred and executed during an active remote session without the necessary authorization or host confirmation. It poses a significant risk to users of the ScreenConnect client, while the servers remain unaffected.
## Technical Details
The vulnerability arises from a condition in the ScreenConnect client. When exploited, it enables attackers to bypass security measures and transfer files during remote sessions. This can occur without the host's knowledge or consent, making it a serious threat to data integrity and confidentiality. The CVSS score for this vulnerability is 9.9, indicating a high level of severity.
## Impact
If exploited, this vulnerability can lead to unauthorized access to sensitive files and execution of malicious code on the host system. Organizations using ScreenConnect should be aware that this flaw could facilitate data breaches or the deployment of ransomware, significantly impacting operations and security posture.
## Mitigation
Defenders should take immediate action to secure their systems. Update the ConnectWise ScreenConnect client to the latest version as soon as possible. Monitor remote sessions for unusual activity and implement strict access controls. Regularly review security policies and train staff on recognizing potential threats related to remote access tools.
CSURFACE Threat Sensor