ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect allows file transfer and execution through active remote sessions without authorization. CVSS 9.9 critical, CISA KEV due September 14.
- Vendor
- ConnectWise
- Product
- ScreenConnect
- CVSS
- 9.9
- EPSS (exploit probability)
- 0.9%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
An attacker with access to an active ConnectWise ScreenConnect remote session can transfer and execute files on the host without additional authorization or host confirmation. The flaw combines improper privilege management with a missing authorization check.
CISA confirmed active exploitation and added CVE-2026-84869 to its Known Exploited Vulnerabilities catalog on September 11, 2026. Federal agencies must remediate by September 14, 2026. ConnectWise’s security bulletin and the NVD entry have patch details. Any internet-exposed ScreenConnect instance should be patched now.
