Executive Summary
ConnectWise has released a critical security update for its ScreenConnect remote access software to address a vulnerability tracked as CVE-2026-84869. This flaw, disclosed in early September 2026, allows attackers to bypass typical authorization checks to transfer and execute files through active remote support and access sessions without confirmation from the user.
Technically, the vulnerability stems from a failure in authentication mechanisms during active sessions (T1210). While no specific threat actor was named as the primary driver for this specific CVE, the report notes a history of nation-state exploitation of ScreenConnect and mentions concurrent 'City-Forum' attacks targeting major SaaS platforms like Salesforce and ServiceNow.
This is a critical risk for Managed Service Providers (MSPs) and enterprises relying on ScreenConnect for remote administration. Unauthorized file execution in these environments often serves as a primary vector for ransomware deployment or broader lateral movement within client networks.
