ConnectWise Patches Critical ScreenConnect Authentication Failure
Score: 4/10

ConnectWise Patches Critical ScreenConnect Authentication Failure

ConnectWise has addressed CVE-2026-84869, a critical authentication failure in ScreenConnect that allows unauthorized file transfer and execution during active remote sessions.

Executive Summary

ConnectWise has released a critical security update for its ScreenConnect remote access software to address a vulnerability tracked as CVE-2026-84869. This flaw, disclosed in early September 2026, allows attackers to bypass typical authorization checks to transfer and execute files through active remote support and access sessions without confirmation from the user.

Technically, the vulnerability stems from a failure in authentication mechanisms during active sessions (T1210). While no specific threat actor was named as the primary driver for this specific CVE, the report notes a history of nation-state exploitation of ScreenConnect and mentions concurrent 'City-Forum' attacks targeting major SaaS platforms like Salesforce and ServiceNow.

This is a critical risk for Managed Service Providers (MSPs) and enterprises relying on ScreenConnect for remote administration. Unauthorized file execution in these environments often serves as a primary vector for ransomware deployment or broader lateral movement within client networks.

Key Details

Threat Name

CVE-2026-84869

Affects

ConnectWise ScreenConnect, ConnectWise Remote Access

Adversary

—

MITRE Techniques

Malware/Tools

None identified

Report Score

4out of 10
Quality Score
Poor
IOC Quality1
TTP Details3
Detection Guidance3
Enterprise Relevance8
Clarity & Structure6
Technical Depth2

Sources