← Back to blog
Blog Detail

CVE-2026-84869: ConnectWise ScreenConnect Privilege and Authorization Flaw Added to CISA KEV

CISA added CVE-2026-84869, a critical ConnectWise ScreenConnect improper privilege management and missing authorization flaw, to the KEV catalog on 2026-09-11 with a due date of 2026-09-14. Patch or mitigate ScreenConnect clients today.

Trusteed Team
Trusteed Editorial
Written On
Sep 18, 2026
Category
CTEM
Read Time
4 min read
  • CVE-2026-84869
  • KEV
  • CISA
  • ConnectWise
  • ScreenConnect
  • CWE-269
  • CWE-862
  • remote-support
  • privilege-management

CVE-2026-84869: ConnectWise ScreenConnect Privilege and Authorization Flaw Added to CISA KEV

TL;DR

CISA added CVE-2026-84869, an improper privilege management and missing authorization vulnerability in ConnectWise ScreenConnect, to the Known Exploited Vulnerabilities catalog on 2026-09-11 with a federal remediation due date of 2026-09-14. Treat this as an urgent remote-support tooling risk: inventory ScreenConnect clients, apply the vendor's mitigations per the ConnectWise security bulletin, and verify that unauthorized file transfer and execution through active remote sessions is no longer possible.

What is this vulnerability?

  • CVE ID: CVE-2026-84869
  • Vendor / product: ConnectWise / ScreenConnect
  • Vulnerability name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
  • Weakness classes: CWE-269 (Improper Privilege Management) and CWE-862 (Missing Authorization)
  • CISA KEV status: Yes — added 2026-09-11
  • CISA due date: 2026-09-14
  • CVSS (per Watchstack): 9.9 CRITICAL, vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • EPSS (per Watchstack): 0.00691 (percentile 0.51195)
  • Known ransomware use: Unknown per CISA KEV entry

Per the official summary, a condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted. CISA's required action is to apply mitigations in accordance with vendor instructions, consistent with BOD 26-04 and the associated Forensics Triage Requirements, and to evaluate each asset's internet exposure.

KEV vs CVSS vs EPSS

Signal What it measures How to use it for this CVE
CISA KEV Confirmed in-the-wild exploitation; carries a binding remediation due date for federal agencies Highest-priority trigger. CVE-2026-84869 was added 2026-09-11 with a due date of 2026-09-14 — schedule remediation immediately and treat as exploited.
CVSS Theoretical severity of the vulnerability (base score and vector) Watchstack reports 9.9 CRITICAL (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Use it to justify emergency change windows and executive escalation, not to deprioritize.
EPSS Probability of exploitation activity in the next 30 days Watchstack reports 0.00691 (percentile 0.51195). Low EPSS does not override KEV; exploitation is already confirmed, so EPSS should not be used to defer patching.

Step-by-step remediation

  1. Inventory. Enumerate all ConnectWise ScreenConnect client installations across endpoints, servers, and golden images. Note version, deployment method, and whether the client is internet-facing or reachable from untrusted networks.
  2. Patch or mitigate. Apply mitigations in accordance with the ConnectWise ScreenConnect security bulletin (2026-09-08). Follow applicable BOD 26-04 guidance for cloud services; if mitigations are unavailable, discontinue use of the product.
  3. Verify. Confirm the updated client is running on all in-scope assets. Validate that file transfer and execution through active remote sessions now require authorization and Host confirmation. Re-scan to catch missed or reverted endpoints.
  4. Restrict exposure. Evaluate each asset's internet exposure and tighten access to ScreenConnect infrastructure and clients consistent with BOD 26-04 patching guidelines.
  5. Hunt and triage. Review remote-session logs for unauthorized file transfers or executions. Apply CISA's Forensics Triage Requirements where compromise is suspected.
  6. Close the ticket. Document the patch version, verification evidence, and any compensating controls. Confirm the KEV due date of 2026-09-14 is met and retain records for audit.

FAQ

Is CVE-2026-84869 in CISA KEV? Yes. CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog on 2026-09-11.

What is the CISA due date? The federal remediation due date is 2026-09-14. Organizations should treat this as an emergency patch window.

Is this vulnerability internet-facing? The CVSS vector (AV:N) indicates network attackability, and CISA directs stakeholders to evaluate each asset's internet exposure. ScreenConnect servers are not impacted per the official summary; the issue is in the ScreenConnect client. Still, remote-support tooling is frequently reachable from untrusted networks, so exposure review is required.

Is there a ransomware tie? CISA's KEV entry lists known ransomware use as Unknown. Absence of a confirmed ransomware link does not reduce urgency given confirmed exploitation.

What is the CVSS score? Watchstack reports 9.9 CRITICAL with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.

What is the EPSS score? Watchstack reports EPSS 0.00691 at the 0.51195 percentile. KEV status takes precedence over low EPSS.

Related resources

Join Our Newsletter

Trusteed keeps you informed: emerging risks, platform updates, and practical guides for faster defense.