CRITICAL
CVE-2026-84869
CVSS
9.9
KEV
Description
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
Weakness (CWE)
CWE-269
Improper Privilege Management
CWE-862
Missing Authorization
EPSS Score
0.69%
Probability of exploitation in next 30 days
51.3th percentile
References
https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-84869
Third Party Advisory
https://www.connectwise.com/company/trust/advisories
Vendor Advisory
https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869
US Government Resource
https://www.huntress.com/blog/rogue-screenconnect-installations
Third Party Advisory
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.