ConnectWise released ScreenConnect version 26.6.5 to address CVE-2026-84869, a critical authentication failure in its remote-access product. The Canadian Centre for Cyber Security reported that open-source reporting showed active exploitation of the flaw in the wild as of September 8, while CSO Online reported that the issue had remained unresolved for five days before the patch was issued.
Organizations running ScreenConnect versions earlier than 26.6.5 should promptly apply the vendor's security update and review ConnectWise security bulletins for associated guidance. Because ScreenConnect provides remote administrative access, defenders should also investigate for unauthorized access or anomalous activity on exposed ScreenConnect infrastructure, particularly where patching was delayed.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
CISA added ConnectWise ScreenConnect vulnerability CVE-2026-84869 to its Known Exploited Vulnerabilities catalog after reports of active exploitation. It set a September 14 federal remediation deadline for affected agencies.
The Canadian Centre for Cyber Security published advisory AV26-903 for CVE-2026-84869 in ConnectWise ScreenConnect and urged users to review vendor guidance and apply updates.
Open-source reporting indicated that CVE-2026-84869, affecting ConnectWise ScreenConnect, was actively exploited in the wild.
Huntress reported that attackers had exploited CVE-2026-84869 since August 20 using modified ScreenConnect clients. The rogue clients used social engineering and deployed VBScript payloads for persistence and propagation to other connected ScreenConnect clients.
ConnectWise released ScreenConnect version 26.6.5 to address the critical authentication-related vulnerability affecting earlier versions. A separate report said the patch arrived five days after the issue was identified or reported.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
7 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourceacn.gov.it
Open sourcethreataft.com
Open sourcecsoonline.com
Open sourcetenable.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.