MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-16 · via BleepingComputer

CISA flags actively exploited ScreenConnect bug, orders federal fixes

Image via BleepingComputer
Image via BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical ConnectWise ScreenConnect vulnerability to its known exploited flaws catalog after confirming active attacks. The flaw, tracked as CVE-2026-84869 and patched in version 26.6.5, allows low-privilege attackers to transfer or execute files without user interaction. More than 1,000 exposed ScreenConnect instances remain unpatched, with most located in North America and Europe.

Expanded Detail

The flaw, CVE-2026-84869, permits attackers with basic privileges to move or execute files during active remote sessions, bypassing host confirmation. Shadowserver counts over 1,000 exposed, unpatched servers, predominantly in North America and Europe. ConnectWise's initial guidance was to disable TransferFiles permissions as a stopgap before the full patch in version 26.6.5.

This marks the fourth ScreenConnect issue CISA has listed as actively exploited since 2024. Previous flaws, such as CVE-2024-1709, were leveraged by the Kimsuky group and ransomware gangs. ConnectWise has also dealt with code-signing certificate rotations and a separate cryptographic verification flaw (CVE-2026-3564) this year, underscoring persistent targeting of its remote access platform.

Context

The active exploitation of this ScreenConnect flaw could disrupt managed service providers and the thousands of businesses that rely on remote access for daily operations. If unpatched servers are compromised, attackers may deploy ransomware or steal sensitive data, potentially causing cascading outages across multiple client networks. Federal agencies face a tight three-day deadline, but the broader private sector may lag, leaving critical infrastructure and small businesses vulnerable to lateral movement and credential theft. The repeated targeting of this platform suggests a systemic risk to remote management tools.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Ransomware Gangs Join Attacks on Unpatched WatchGuard Fireboxes · Cybersecurity
Ransomware groups escalate attacks on unpatched VMware vCenter servers · Cybersecurity
CISA flags active exploitation of critical GitLab vulnerability · Cybersecurity
Cisco warns of active exploitation of critical firewall management flaw · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Critical ScreenConnect flaw now actively exploited in attacks.” Browse more stories.