Vulnerable ScreenConnect client/agent version prior to 26.6.5 (CVE-2026-84869)
This rule monitors IT asset inventory data for instances of ConnectWise (ScreenConnect) software running outdated versions prior to 26.6.5, which are known to be vulnerable to CVE-2026-84869. Identifying these assets is critical for preventing potential exploitation of public-facing remote administration tools.
Splunk (SPL)

