Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2815+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
NEWS

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

CVE-2026-84869 (CVSS 9.9) let attackers push and execute files through active ScreenConnect sessions, spreading VBScript payloads since August 20.

Dylan H.

News Desk

September 14, 2026
3 min read

Critical Flaw Turned RMM Sessions Into a Spreading Mechanism

ConnectWise has patched a critical vulnerability in its widely deployed ScreenConnect remote monitoring and management (RMM) tool after it was exploited in worm-like attacks that propagated across connected client sessions.


Vulnerability Details

AttributeValue
CVE IDCVE-2026-84869
CVSS Score9.9 (Critical)
Root CauseMissing authorization and improper privilege management
ExploitationTransfer and execute files through an active remote session without authorization
Discovered ExploitingAugust 20, 2026
Discovered ByHuntress
Patched VersionScreenConnect 26.6.5
Vendor BulletinSeptember 8, 2026

How the Attacks Spread

Threat actors deployed modified ScreenConnect instances to propagate malicious payloads to connected targets. Documented campaigns involved four malicious VBScript files designed to establish persistence and self-replicate across systems reachable through active remote sessions. Social engineering was used to trick users into running the rogue ScreenConnect clients in the first place, after which the file-transfer/execute flaw allowed the attack to spread without further authorization checks.

Because ScreenConnect is deployed by MSPs to manage large numbers of downstream client endpoints, a single compromised technician session could give attackers a path to numerous connected environments.


Patch and Mitigation

ConnectWise resolved the issue in ScreenConnect 26.6.5, which "strengthens client and session handling for file-transfer and file-execution actions."

Recommended Actions

  1. Update to ScreenConnect 26.6.5 or later immediately.
  2. Temporarily disable the TransferFiles permission in ScreenConnect if you cannot patch right away.
  3. Audit active and historical sessions for unauthorized file transfers or execution of unrecognized VBScript files.
  4. Federal agencies are required to patch within three days under the CISA Known Exploited Vulnerabilities (KEV) catalog mandate (BOD 26-04), reflecting the severity and active exploitation status.
  5. MSPs specifically should treat this as urgent — worm-like propagation through RMM tooling can rapidly cascade across every downstream client tenant.

Why This Matters

RMM platforms like ScreenConnect sit at a uniquely privileged point in the supply chain: a single MSP technician's session often has administrative reach into dozens or hundreds of client networks. Vulnerabilities that enable unauthorized file transfer and execution inside that trust relationship — especially ones capable of worm-like spread — represent some of the highest-leverage targets for ransomware affiliates and other financially motivated threat actors.


Related Reading

  • Surge in Bomgar RMM Exploitation Demonstrates Supply Chain Risk
  • CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV
#Vulnerability#Security Updates#ConnectWise#ScreenConnect#RMM#CVE-2026-84869

Related Articles

CVE-2026-84869: ConnectWise ScreenConnect Unauthorized File Transfer & Execution

A critical ScreenConnect client flaw lets attackers transfer and execute files through active remote sessions without host confirmation.

5 min read

CVE-2024-1708: ConnectWise ScreenConnect Path Traversal

ConnectWise ScreenConnect contains a path traversal vulnerability (CVE-2024-1708) that allows attackers to execute remote code or directly access...

6 min read

CVE-2026-3564: ConnectWise ScreenConnect Auth Bypass via Server Cryptographic Material

A critical authentication bypass vulnerability (CVSS 9.0) in ConnectWise ScreenConnect versions prior to 26.1 allows an actor with access to server-level...

3 min read
Back to all News