---
id: CVE-2026-84869
title: >-
  A condition in the ScreenConnect client may allow files to be transferred and
  executed through an active remote session without authorization or Host
  confirmation in certain circumstances
summary: >-
  A condition in the ScreenConnect client may allow files to be transferred and
  executed through an active remote session without authorization or Host
  confirmation in certain circumstances. ScreenConnect servers are not impacted.
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-269
  - CWE-862
vendor: connectwise
product: screenconnect
affected:
  - screenconnect < 26.6.5.9742
patched:
  - screenconnect 26.6.5.9742
published: '2026-09-08'
updated: '2026-09-12'
sourceUpdated: '2026-09-12T04:16:42.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84869'
references:
  - url: >-
      https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-84869
    label: 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
  - url: 'https://www.connectwise.com/company/trust/advisories'
    label: 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
  - url: >-
      https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin
    label: 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://www.huntress.com/blog/rogue-screenconnect-installations'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T18:50:39.725092Z'
epss: 0.00924
epssPercentile: 0.58715
kev: true
kevDateAdded: '2026-09-11'
kevDueDate: '2026-09-14'
kevRansomware: false
ingestedAt: '2026-09-08T20:10:03.222Z'
---

## Overview

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

## Affected

- `screenconnect < 26.6.5.9742`

## Remediation

Upgrade past the affected range:

- `screenconnect 26.6.5.9742`
