๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
Summary
ConnectWise ScreenConnect has a vulnerability that allows attackers to transfer files and run code through remote sessions without proper authorization checks. This happens because the software doesn't properly manage user permissions (improper privilege management, where access controls aren't correctly enforced) and is missing authorization checks (verification that users should be allowed to do what they're attempting). This vulnerability is currently being actively exploited by attackers.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions per ConnectWise's security bulletin (https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin), ensuring compliance with CISA's BOD 26-04 guidance. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. The due date for applying these mitigations is 2026-09-14.
Vulnerability Details
EPSS: 0.4%
Yes
๐ฅ Actively Exploited
September 10, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-84869
First tracked: September 11, 2026 at 08:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%