ConnectWise disclosed an unnumbered security issue affecting file-transfer behavior in ScreenConnect Remote Access Support and Access sessions. The issue affects both cloud-hosted and self-hosted ScreenConnect deployments; the company had not released exploit details, affected-version information, or evidence of active exploitation.
Until cloud updates and a permanent patched release are available, ConnectWise advised administrators to remove technician file-transfer privileges from applicable roles, including TransferFiles and the legacy TransferFilesInSession permission. Organizations should review privileged ScreenConnect accounts and monitor for unusual file-transfer activity or changes to role permissions; a CVE is expected after the cloud-environment rollout is complete.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
ConnectWise advisory and bulletin references identified CVE-2026-84869 as an authorization flaw in the ScreenConnect client that can permit unauthorized file transfer and execution through an active remote session in certain circumstances. The CVE states that ScreenConnect servers are not affected and assigns a CVSS 3.1 score vector indicating high confidentiality, integrity, and availability impact.
ConnectWise published an advisory for an unnumbered security issue in ScreenConnect Remote Access file-transfer behavior affecting Support and Access sessions in both cloud-hosted and self-hosted deployments. It advised administrators to immediately remove TransferFiles or legacy TransferFilesInSession permissions while it completes cloud updates and develops a permanent fix.
ConnectWise stated that it remediated ScreenConnect cloud servers and that ScreenConnect 26.6.5 and later remediate CVE-2026-84869 for affected host clients and access agents. It advised customers to upgrade, including through Automate Product Updates for integrated deployments; removing TransferFiles remains a temporary mitigation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceconnectwise.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.