ScreenConnect Zero-Day Now Under Active Attack

▼ Summary
– The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical, actively exploited vulnerability in ConnectWise ScreenConnect known as CVE-2026-84869.
– This missing-authorization flaw allows attackers with basic privileges to transfer or execute files without user interaction or host confirmation.
– CISA ordered federal agencies to secure their systems within three days and added the flaw to its catalog of actively exploited vulnerabilities.
– Shadowserver reports that over 1,000 unpatched ScreenConnect instances remain exposed online, primarily located in North America and Europe.
– Historical data shows ScreenConnect has been targeted by multiple hacking groups since 2024, including state-sponsored actors and ransomware gangs.
Active Exploitation of ScreenConnect Flaw
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that threat actors are actively exploiting a critical vulnerability in ConnectWise’s ScreenConnect software. This zero-day flaw, identified as CVE-2026-84869, allows attackers to bypass security controls with minimal effort. The agency added the issue to its catalog of actively exploited vulnerabilities on Friday and issued an urgent directive for U. S. federal agencies to implement protections within three days.
In response to the immediate threat, ConnectWise released temporary mitigation steps on September 7. The company advised security teams to disable TransferFiles permissions to prevent potential attacks while they worked on a permanent solution. The flaw affects ScreenConnect clients and enables individuals with basic privileges to transfer or execute files during active remote sessions. These attacks are characterized by their low complexity and do not require any user interaction to succeed.
“The types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise,” CISA stated regarding the dual nature of the flaw. “ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.”
Widespread Exposure and Historical Context
Since 2024, CISA has flagged four separate ScreenConnect security issues as being actively exploited in the wild. Two of these prior incidents were also linked to ransomware campaigns, highlighting the severe impact of these breaches. The current unpatched instances represent a significant surface area for attackers. Internet threat monitoring firm Shadowserver now tracks over 1,000 exposed ScreenConnect instances online. The majority of these vulnerable systems are located in North America, accounting for 758 instances, followed by Europe with 180 cases.
This pattern of targeting is consistent with previous activities by both financially motivated groups and state-backed hacking organizations. For example, the North Korean-linked Kimsuky hacking group and various ransomware syndicates exploited another ScreenConnect flaw, CVE-2024-1709, in 2024. The supply chain integrity of the software provider itself has also been compromised in the past. Last year, ConnectWise was forced to rotate digital code-signing certificates after disclosing that suspected state-sponsored hackers breached its systems. Those intruders utilized code injection attacks targeting a ViewState flaw (CVE-2025-3935) to access cloud-based instances belonging to a limited number of customers.
Ongoing Security Challenges for MSPs
The pressure on ConnectWise to secure its platform remains high due to the breadth of its customer base. The company provides services to more than 100,000 IT providers globally. Many managed service providers (MSPs) rely on the ScreenConnect remote access platform for essential tasks such as troubleshooting, patching, and system maintenance. This widespread adoption makes every vulnerability a high-stakes event for the broader IT community.
Most recently, in March, ConnectWise addressed a cryptographic signature verification vulnerability (CVE-2026-3564) that could have allowed attackers to hijack unpatched servers. The rapid succession of these security events underscores the importance of immediate patching. Organizations using ScreenConnect must ensure they are running version 26.6.5 or later to protect against the currently active exploitation of CVE-2026-84869. Until all instances are updated, the risk of unauthorized file transfers and execution remains acute for global IT operations.
(Source: BleepingComputer)


