ScreenConnect Worm Attacks: CVE-2026-84869 Now Patched
Huntress documented worm-like ScreenConnect attacks active since August 20. ConnectWise has released version 26.6.5 patching CVE-2026-84869, a CVSS 9.9 flaw exploited in the campaign.

Exploitation confirmed. ConnectWise has released ScreenConnect 26.6.5 patching CVE-2026-84869 (CVSS 9.9, critical). The flaw has been under active exploitation since at least August 20, 2026, per Huntress research. Today is the federal patch deadline under CISA’s BOD 26-04.
What the flaw does
CVE-2026-84869 allows file transfer and execution through an active ScreenConnect session without host authorization or confirmation. An attacker who can interact with a session can deliver and run arbitrary files on the connected endpoint, bypassing the host-side approval gate.
Campaign mechanics
Huntress documented the exploitation pattern. Threat actors used social engineering to trick targets into running rogue ScreenConnect client instances. Once a rogue client established a session, it scanned for other active ScreenConnect sessions on the same host. Four VBScript payloads were then pushed through those sessions, designed for persistence and lateral spread to additional ScreenConnect clients. The pattern Huntress describes as “worm-like”: one compromised session begets multiple new attack vectors on connected endpoints.
Attribution: none confirmed. Confidence on scope: limited to what Huntress has published.
Patch and mitigation
Patch: ScreenConnect 26.6.5. ConnectWise describes the update as including “updates to strengthen client and session handling for file-transfer and file-execution actions.”
Interim mitigation, if 26.6.5 is not yet deployed: disable the TransferFiles permission in ScreenConnect. That removes the attack surface for the file-delivery vector.
CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog earlier this week with a federal patch deadline of September 14. The timeline and KEV details are in the September 13 deadline roundup.
Prior ScreenConnect history
CVE-2026-84869 arrives alongside a pattern of remote-access tool exploitation documented across the current KEV cohort. The JFrog Artifactory backdoor campaign in the same CISA batch reached administrative control via chained CVEs. Different products, same operational theme: attackers targeting IT management and remote access tooling.
Instances exposed to the internet are in scope for active exploitation. The TransferFiles mitigation removes the file-delivery vector; 26.6.5 patches the underlying flaw.
- [ CRITICAL ]CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
Found this useful? Share it.


