CISA flags actively exploited ScreenConnect bug, orders federal fixes

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical ConnectWise ScreenConnect vulnerability to its known exploited flaws catalog after confirming active attacks. The flaw, tracked as CVE-2026-84869 and patched in version 26.6.5, allows low-privilege attackers to transfer or execute files without user interaction. More than 1,000 exposed ScreenConnect instances remain unpatched, with most located in North America and Europe.
The flaw, CVE-2026-84869, permits attackers with basic privileges to move or execute files during active remote sessions, bypassing host confirmation. Shadowserver counts over 1,000 exposed, unpatched servers, predominantly in North America and Europe. ConnectWise's initial guidance was to disable TransferFiles permissions as a stopgap before the full patch in version 26.6.5.
This marks the fourth ScreenConnect issue CISA has listed as actively exploited since 2024. Previous flaws, such as CVE-2024-1709, were leveraged by the Kimsuky group and ransomware gangs. ConnectWise has also dealt with code-signing certificate rotations and a separate cryptographic verification flaw (CVE-2026-3564) this year, underscoring persistent targeting of its remote access platform.
The active exploitation of this ScreenConnect flaw could disrupt managed service providers and the thousands of businesses that rely on remote access for daily operations. If unpatched servers are compromised, attackers may deploy ransomware or steal sensitive data, potentially causing cascading outages across multiple client networks. Federal agencies face a tight three-day deadline, but the broader private sector may lag, leaving critical infrastructure and small businesses vulnerable to lateral movement and credential theft. The repeated targeting of this platform suggests a systemic risk to remote management tools.