Skip to content

CVE-2026-84869

ScreenConnect client guest-to-host file execution allows unauthorized code execution (CVE-2026-84869)

Critical 9.9 KEV Published

ScreenConnect clients before 26.6.5 are affected by a critical guest-to-host file execution vulnerability rated 9.9. CISA lists it as exploited. Update clients to 26.6.5.9742; ScreenConnect servers are not impacted.

What happened

CVE-2026-84869 is a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. In practical terms, an attacker with low privileges in a session can move a file to the host and run it without the host approving the action.

The CVSS 3.1 vector rates this 9.9 Critical: it is reachable over the network, requires low privileges, needs no user interaction, and can affect resources beyond the vulnerable system, with high impact to confidentiality, integrity and availability. ScreenConnect servers are not impacted.

CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 11 September 2026, with a due date of 14 September 2026, and CISA SSVC marks exploitation as active.

Who is affected

This affects ScreenConnect client installations on all versions prior to 26.6.5. ScreenConnect is a remote support and remote access tool, so affected organisations are those running the client on endpoints used in support sessions. ScreenConnect servers are not impacted by this CVE.

What to do now

  1. Update ScreenConnect clients to the fixed version, ScreenConnect 26.6.5.9742.
  2. Prioritise client installations that participate in remote sessions, since the flaw is in the client and ScreenConnect servers are not impacted.
  3. Follow CISA's KEV required action: apply mitigations in accordance with vendor instructions and evaluate each asset's internet exposure. If the update cannot be applied, CISA advises discontinuing use of the product where mitigations are unavailable.
  4. Review remote sessions for file-transfer activity that was not approved by the host.

How to detect it

ScreenConnect is a remote access tool, and CISA's KEV entry instructs organisations to evaluate each asset's internet exposure. As a starting point, inventory ScreenConnect client installations to confirm they are at the fixed version 26.6.5.9742, and review active or recent sessions for file transfers from guest sessions that the host did not approve.

Beyond the patch

Because CISA KEV lists this as exploited and CISA SSVC marks active exploitation, patching is the immediate step but detection and response also matter. Managed Detection & Response can help watch for post-exploitation activity on systems where ScreenConnect clients run, and an Incident Response Retainer gives you a tested route to respond if a session was abused before the update. A remote access tool also deserves third-party scrutiny; see our Supply Chain Defense & Third-Party Risk service.

Affected and fixed versions

ProductAffectedFixed in
ScreenConnectAll versions prior to 26.6.526.6.5.9742

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.