A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
References
| Link | Resource |
|---|---|
| https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-84869 | Third Party Advisory |
| https://www.connectwise.com/company/trust/advisories | Vendor Advisory |
| https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869 | US Government Resource |
| https://www.huntress.com/blog/rogue-screenconnect-installations | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-09-08 20:18
Updated : 2026-09-12 04:16
NVD link : CVE-2026-84869
Mitre link : CVE-2026-84869
CVE.ORG link : CVE-2026-84869
JSON object : View
Products Affected
connectwise
- screenconnect
