A critical security flaw in ConnectWise ScreenConnect, a remote access tool widely used by IT support providers, is being actively exploited by attackers.
- What it is: CVE-2026-84869 is a critical flaw (CVSS 9.9) in ScreenConnect that lets an attacker with an active remote session transfer and run files on a connected system without authorisation or approval from the host.
- Who is affected: Any business whose IT provider uses ScreenConnect for remote support, and any organisation running its own ScreenConnect server that has not applied the September update.
- What the risk is: Security researchers have confirmed real-world attacks using this flaw to push malicious scripts to connected systems, and more than 1,000 exposed ScreenConnect servers remain unpatched online.
- What to do: Confirm with your IT provider that ScreenConnect has been updated to version 26.6.5 or later, and that file-transfer permissions are locked down on any older instance still in use.
We recommend businesses using ScreenConnect for remote support confirm with their provider that this update has been applied, given the flaw is already being used in live attacks.
Source: BleepingComputer