The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical ConnectWise ScreenConnect vulnerability, tracked as CVE-2026-84869, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming that threat actors are actively exploiting the flaw in attacks.
The issue affects ScreenConnect, a widely used remote monitoring and support platform that enables administrators and managed service providers to access endpoints remotely.
CVE-2026-84869 is an improper privilege management and missing authorization vulnerability. In practical terms, the flaw could allow an attacker to transfer files to a device and execute them during an active remote ScreenConnect session without obtaining authorization or receiving confirmation from the host user.
The vulnerability is mapped to CWE-269, Improper Privilege Management, and CWE-862, Missing Authorization. The flaw is particularly significant because remote-access tools occupy a trusted position in many enterprise networks.
ScreenConnect Vulnerability Exploited
If an attacker can abuse an active session, they may deliver malicious payloads, run unauthorized tools, establish persistence, or move deeper into an affected environment while appearing to use legitimate remote-management infrastructure.
Such platforms are frequently targeted because a compromise can provide access to multiple managed systems, especially in environments supported by IT service providers.
CISA added CVE-2026-84869 to the KEV Catalog on September 11, 2026, and set a remediation deadline of September 14, 2026, for organizations covered by Binding Operational Directive 26-04.
The agency also flagged the vulnerability as requiring forensic triage under the directive, indicating that affected organizations should not treat patching as the sole response.
Security teams should determine whether ScreenConnect instances were internet-exposed, identify potentially affected hosts and sessions, and review available logs for suspicious file-transfer or execution activity.
ConnectWise has published a security bulletin addressing the ScreenConnect issue and provides vendor guidance for mitigation.
Organizations should apply the vendor’s recommended fixes immediately, validate that every ScreenConnect server and managed endpoint is covered, and restrict external access wherever possible.
According to the advisory catalog published by CISA, CISA advised stakeholders to assess each asset’s internet exposure and follow BOD 26-04 risk-based update requirements; where mitigations are unavailable, organizations should discontinue use of the affected product.
Defenders should also review ScreenConnect administrative accounts, active and historical remote sessions, file-transfer records, child processes launched through ScreenConnect, and outbound connections from systems hosting the service.
Credential resets and session-token invalidation may be appropriate where suspicious activity is detected. While CISA’s entry does not identify confirmed ransomware use, active exploitation means organizations should assume that opportunistic and targeted attackers may rapidly incorporate the vulnerability into intrusion workflows.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
The post CISA Warns of Critical ScreenConnect Vulnerability Actively Exploited in Attacks appeared first on Cyber Security News.
