Exploited in the wild ConnectWise ScreenConnect rce ConnectWise malware
ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
CVE Tools coverage
ConnectWise has deployed urgent patches for a critical vulnerability identified as CVE-2026-84869, which allows unauthorized file transfer and execution within active ScreenConnect sessions. This flaw, rated 9.9 on the CVSS scale, has been actively exploited in worm-like campaigns where attackers use social engineering to spread malicious payloads between clients.
To address the threat, users should update to ScreenConnect version 26.6.5 immediately, which strengthens session handling and file-transfer permissions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this CVE to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply the fix within three days.