CVE-2026-84869
ScreenConnect client guest-to-host file execution allows unauthorized code execution (CVE-2026-84869)
ScreenConnect clients before 26.6.5 are affected by a critical guest-to-host file execution vulnerability rated 9.9. CISA lists it as exploited. Update clients to 26.6.5.9742; ScreenConnect servers are not impacted.
What happened
CVE-2026-84869 is a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. In practical terms, an attacker with low privileges in a session can move a file to the host and run it without the host approving the action.
The CVSS 3.1 vector rates this 9.9 Critical: it is reachable over the network, requires low privileges, needs no user interaction, and can affect resources beyond the vulnerable system, with high impact to confidentiality, integrity and availability. ScreenConnect servers are not impacted.
CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 11 September 2026, with a due date of 14 September 2026, and CISA SSVC marks exploitation as active.
Who is affected
This affects ScreenConnect client installations on all versions prior to 26.6.5. ScreenConnect is a remote support and remote access tool, so affected organisations are those running the client on endpoints used in support sessions. ScreenConnect servers are not impacted by this CVE.
What to do now
- Update ScreenConnect clients to the fixed version, ScreenConnect 26.6.5.9742.
- Prioritise client installations that participate in remote sessions, since the flaw is in the client and ScreenConnect servers are not impacted.
- Follow CISA's KEV required action: apply mitigations in accordance with vendor instructions and evaluate each asset's internet exposure. If the update cannot be applied, CISA advises discontinuing use of the product where mitigations are unavailable.
- Review remote sessions for file-transfer activity that was not approved by the host.
How to detect it
ScreenConnect is a remote access tool, and CISA's KEV entry instructs organisations to evaluate each asset's internet exposure. As a starting point, inventory ScreenConnect client installations to confirm they are at the fixed version 26.6.5.9742, and review active or recent sessions for file transfers from guest sessions that the host did not approve.
Beyond the patch
Because CISA KEV lists this as exploited and CISA SSVC marks active exploitation, patching is the immediate step but detection and response also matter. Managed Detection & Response can help watch for post-exploitation activity on systems where ScreenConnect clients run, and an Incident Response Retainer gives you a tested route to respond if a session was abused before the update. A remote access tool also deserves third-party scrutiny; see our Supply Chain Defense & Third-Party Risk service.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| ScreenConnect | All versions prior to 26.6.5 | 26.6.5.9742 |