ScreenConnect Flaw Under Attack, Patch Urged
CISA orders federal agencies to fix a critical ConnectWise ScreenConnect flaw exploited in the wild, with over 1,000 instances still exposed.
A critical authorization flaw in ConnectWise's ScreenConnect remote access tool is now being exploited in live attacks, prompting the U.S. Cybersecurity and Infrastructure Security Agency to add it to its catalog of actively exploited flaws and give federal agencies three days to secure their systems. The bug, tracked as CVE-2026-84869, lets attackers with only basic privileges move and run files on vulnerable servers, and more than a thousand internet-facing instances remain unpatched.
What the Flaw Allows
According to CISA, the vulnerability combines two distinct weaknesses: improper privilege management and missing authorization. Together they may let an attacker transfer and execute files through an active remote session without the host's authorization or confirmation. That means the victim does not need to click anything or approve a prompt — the session itself becomes the delivery path.
The agency describes the attack complexity as low and notes that no user interaction is required. An adversary who already holds basic privileges on a ScreenConnect instance can leverage the flaw to push files onto the target and run them. ConnectWise patched the issue in ScreenConnect version 26.6.5 and later.
Three-Day Deadline for Federal Agencies
CISA added the flaw to its catalog of actively exploited vulnerabilities on Friday and ordered U.S. federal agencies to secure their systems against ongoing attacks within three days. That timetable is among the shortest the agency applies, reserved for bugs it believes are being used right now against real targets.
The agency framed the risk in stark terms:
"ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation," CISA said. "These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise."
— CISA, U.S. Cybersecurity and Infrastructure Security Agency
Interim Mitigation Before Patching
Before a patch was available, ConnectWise shared temporary mitigation measures on September 7, advising security teams to disable TransferFiles permissions to block potential attacks. That step removes the file-transfer capability the flaw depends on, cutting off the most direct exploitation path while administrators prepare to upgrade.
Organizations that have not yet applied the fix should treat the TransferFiles change as a stopgap, not a permanent solution. Upgrading to ScreenConnect 26.6.5 or later restores full functionality while closing the underlying authorization gap.
Over 1,000 Exposed Instances
Internet threat watchdog Shadowserver now tracks over 1,000 ScreenConnect instances that remain unpatched and exposed online, according to the source. The geographic breakdown shows most of the vulnerable systems are in North America (758), followed by Europe (180).
Those figures matter because ScreenConnect is widely deployed by managed service providers and IT teams for troubleshooting, patching and remote maintenance. An exposed instance is not just a single company's problem — it can be a foothold into every customer that relies on that provider.
A Repeated Target for Attackers
ScreenConnect vulnerabilities are often targeted in the wild by both financially motivated and state-backed hacking groups. Since 2024, CISA has flagged four ScreenConnect security issues as actively exploited, two of which have also been abused in ransomware attacks.
The North Korean-backed Kimsuky hacking group and several ransomware gangs exploited another ScreenConnect flaw, CVE-2024-1709, in 2024. That history shows the platform sits on a shortlist of remote-access tools that attackers return to whenever a new weakness appears.
Earlier Breaches and Certificate Rotation
Last year, ConnectWise rotated digital code-signing certificates after disclosing that suspected state-sponsored hackers breached its systems through code injection attacks that exploited a ViewState flaw (CVE-2025-3935) and accessed the cloud-based instances of a limited number of customers.
More recently, in March, ConnectWise addressed a cryptographic signature verification vulnerability (CVE-2026-3564) that could allow attackers to hijack unpatched ScreenConnect servers. The pattern of repeated fixes is part of why CISA treats each new ScreenConnect flaw as urgent rather than routine.
Scale of the ScreenConnect Footprint
ConnectWise provides services to more than 100,000 IT providers worldwide, with many managed service providers and IT teams using its ScreenConnect remote access platform for troubleshooting, patching and system maintenance. That reach explains why a single authorization flaw can ripple across thousands of downstream organizations.
For MSPs, the exposure is twofold: their own infrastructure may be vulnerable, and their clients' environments may be reachable through a compromised management session. The Shadowserver data on unpatched instances is a direct measure of how much of that surface remains open.
Key Figures Behind the Alert
- CVE-2026-84869 — the critical ScreenConnect flaw now exploited in the wild
- 26.6.5 — the ScreenConnect version that fixes the issue and later
- September 7 — date ConnectWise shared temporary mitigation measures
- Three days — deadline CISA gave federal agencies to secure systems
- Over 1,000 — ScreenConnect instances still unpatched and exposed, per Shadowserver
- 758 — exposed instances in North America; 180 in Europe
- Four — ScreenConnect issues CISA has flagged as actively exploited since 2024
- 100,000+ — IT providers worldwide served by ConnectWise
What Patching and Mitigation Demand
Security teams running ScreenConnect should verify their version and move to 26.6.5 or later as soon as possible. Where an upgrade cannot be completed immediately, disabling TransferFiles permissions remains the recommended interim step, according to ConnectWise's September 7 guidance.
Because the flaw requires no user interaction, defenders cannot rely on employee awareness training to stop it. The window for action is set by CISA's three-day directive for federal agencies, and the Shadowserver tally shows a substantial number of organizations outside that mandate are still exposed.
Why This Matters Beyond Federal Networks
The three-day order applies to U.S. federal agencies, but the vulnerable software is used far more widely by MSPs and private IT teams. A flaw that lets attackers transfer and execute files through an active session can turn a trusted remote-support channel into a delivery mechanism, and the Shadowserver count of over 1,000 exposed instances suggests many organizations have not yet acted.
This could mean that the most immediate risk sits with smaller providers and their clients, who may lack the staff to track CISA catalog updates or ConnectWise advisories in real time. The repeated history of ScreenConnect exploitation — four flagged issues since 2024, including CVE-2024-1709 used by Kimsuky and ransomware gangs — suggests attackers already know where to look. For MSPs, the practical takeaway is to inventory ScreenConnect deployments, confirm patch levels, and treat any internet-facing instance that has not been updated as an active liability rather than a pending ticket. The source material does not indicate how many of the exposed instances belong to federal agencies versus private operators, so the true scope of ongoing exploitation remains unclear.
Sources
- BleepingComputer Original source
Continue Reading
WooCommerce Plugin Flaw Fuels Web Shell Attacks
Attackers are exploiting a critical WooCommerce Wholesale Lead Capture vulnerability to upload PHP web shells and achieve remote code execution.
Pixel Zero-Day Patched After Targeted Attacks
Google's September 2026 Pixel update fixes 110 flaws, including a modem zero-day exploited in limited, targeted attacks.
Cyberattacks Cost Firms $52,000 on Average
Hiscox report finds 29% of organizations hit by cyberattacks in the past year, with average costs of $52,000 and 32.8 hours of downtime.