## Overview
CISA added CVE-2026-84869 to its Known Exploited Vulnerabilities (KEV) list on September 11, 2026. This vulnerability affects ConnectWise ScreenConnect, allowing unauthorized file transfers and execution during active remote sessions. The addition to the KEV list indicates a federal deadline for mitigation, emphasizing the urgency of the issue.
## Technical Details
The vulnerability arises from improper privilege management and missing authorization checks within the ScreenConnect client. Attackers can exploit this flaw to transfer files and execute them without the host's confirmation. Notably, the ScreenConnect servers are not impacted by this vulnerability, limiting the scope of potential exploitation to client-side interactions.
## Impact
With a CVSS score of 9.9, this vulnerability poses a significant risk. Attackers can leverage it to gain unauthorized access to systems during remote sessions, potentially leading to data breaches or further compromise of the network. Organizations using ScreenConnect should be aware that exploitation can occur without any indication to the host, making detection challenging.
## Mitigation
ConnectWise has released patches to address this vulnerability. Organizations using ScreenConnect should prioritize applying these updates immediately. Regularly review security configurations and ensure that proper authorization mechanisms are in place. Additionally, monitor remote session activities for any unauthorized actions to enhance security.
CSURFACE Threat Sensor