Trending: On-device modelsSearch
iHeartGeek
iTECH

ConnectWise patches critical ScreenConnect auth flaw

ScreenConnect client 26.6.5 closes CVE-2026-84869, which let files be transferred and executed through active remote sessions without permission.

ConnectWise executive Manny Rivelo speaking at a company event, official ConnectWise photo credited via Computerworld

ConnectWise has shipped a security update for ScreenConnect, ending a five-day stretch in which admins were told to manually defuse a flaw that let files be transferred and executed through active remote sessions without authorisation or confirmation. The fix lands in ScreenConnect client version 26.6.5 onwards.

As Computerworld reports, ConnectWise first warned customers on 3 September about the problem with support and access sessions in ConnectWise Remote Access, advising admins to log in and strip the "TransferFiles" permission from any users with an open session. The vulnerability is tracked as CVE-2026-84869.

What's actually going on

The flaw sat in ScreenConnect's remote support and access workflows: a guest could, under the wrong conditions, push files onto a host machine and execute them without the usual confirmation prompts. ConnectWise's interim mitigation was deliberately blunt — remove file-transfer permissions from live sessions entirely until a proper patch arrived.

That patch is now here. According to the report, ScreenConnect client 26.6.5 and later close CVE-2026-84869, so the practical instruction for IT teams is straightforward: update every ScreenConnect installation, then re-enable file transfer for the accounts that genuinely need it.

It is also the latest entry in an uncomfortable pattern. In 2024 ConnectWise patched ScreenConnect after reports of active exploitation, and in May 2025 the company dealt with a "nation-state attack" that affected several customers — insisting at its IT Nation Connect Asia Pacific conference last month that it was back on track and that no customers suffered loss, as Computerworld notes.

Why you should care

ScreenConnect is remote-access software, which means it is effectively a front door to thousands of endpoints. Any flaw that lets an unauthorised file land and run through an active session is about as bad as it gets short of full system takeover — the attacker skips the phishing entirely and lets the legitimate support tool do the delivery.

If you run ScreenConnect or ConnectWise Remote Access, patching is not a this-week job; it is a today job. Anything still exposing the TransferFiles permission on an unpatched client is carrying an unlocked side door with a welcome mat on it.

Our opinion

Credit where due: ConnectWise shipped a workaround within days and a full patch within the working week, which is better than many vendors manage. But this is the third ScreenConnect security incident in roughly two years, and remote-access tools get exactly one reputation. Every unpatched client on a network is a liability the IT team chose to keep.

Patch to 26.6.5 now, audit who still holds the TransferFiles permission afterwards, and if ScreenConnect keeps appearing in your incident reports, it may be time to ask whether the convenience is worth the recurring anxiety.

What we know
  • ConnectWise released a security update for ScreenConnect on 11 September 2026, five days after its 3 September warning
  • The flaw, CVE-2026-84869, allowed file transfer and execution through active sessions without authorisation
  • The interim mitigation was removing the TransferFiles permission from users with open sessions
  • The fix ships in ScreenConnect client 26.6.5 and later
  • ConnectWise previously patched ScreenConnect exploits in 2024 and responded to a May 2025 nation-state attack