CVE-2026-84869, a CVSS 9.9 flaw in ConnectWise ScreenConnect’s client, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 11, 2026. NVD’s scoring places it near the top of the scale — network-exploitable, low attack complexity, requiring only low privileges and no user interaction, with a scope change and high impact across confidentiality, integrity, and availability.
What the vulnerability does
NVD tracks CVE-2026-84869 under CWE-269 (Improper Privilege Management) and CWE-862 (Missing Authorization). Per NVD’s description, a condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation, in certain circumstances. ConnectWise’s own advisory data (surfaced in CISA’s KEV entry) is explicit that ScreenConnect servers are not affected — this is a client-side flaw specific to sessions already established through the remote-support agent.
Why it’s on KEV
CISA’s September 11 KEV addition requires federal civilian agencies to remediate per Binding Operational Directive (BOD) 26-04. ConnectWise has published a dedicated security bulletin (2026-09-08-screenconnect-bulletin) and disclosure notes on GitHub. Independent research from Huntress, a managed-detection vendor with visibility into RMM (remote monitoring and management) tooling abuse, has separately documented “rogue ScreenConnect installations” being used as an attack vector — consistent with, though not confirmed by NVD as directly describing, this specific CVE.
What we don’t yet have
Our pipeline currently traces CVSS scoring and the vulnerability description to NVD alone, with no second independent scoring source yet corroborating the 9.9 figure — so we’re marking confidence medium on severity, even though the exploitation status itself (via CISA KEV, an authoritative source for that specific claim) is well-supported. We also don’t have an EPSS exploitation-probability score or affected version-range data ingested yet for this CVE.
Why this matters
ScreenConnect and similar remote-support tools are a favored initial-access and lateral-movement vector precisely because they’re often already trusted and allow-listed on target networks — a flaw that lets an attacker execute files through an already-active session without the Host’s confirmation removes one of the few remaining checkpoints an operator would normally rely on to notice something is wrong. Because the flaw is client-side and requires an active session rather than open exposure, patch prioritization should weight environments where ScreenConnect clients are broadly deployed to end-user or server endpoints, not just internet-facing ScreenConnect servers (which NVD’s description explicitly excludes from impact).
Frequently Asked Questions
What is CVE-2026-84869? A CVSS 9.9 improper-privilege-management and missing-authorization flaw in the ConnectWise ScreenConnect client that can allow file transfer and execution through an active remote session without Host confirmation.
Is CVE-2026-84869 being actively exploited? Yes — CISA added it to the Known Exploited Vulnerabilities catalog on September 11, 2026.
Are ScreenConnect servers affected? No. Per ConnectWise’s own advisory data, this flaw is specific to the ScreenConnect client; ScreenConnect servers are not impacted.
Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 12, 2026. See more vulnerability intelligence.