Security
Loading…

CVE-2026-84869

CRITICALCVSS 9.9Known Exploited
Description

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.

Timeline
Published:September 8th, 2026 8:18 PM
Last modified:September 12th, 2026 4:16 AM
Added to KEV:September 11th, 2026
CVSS Scoring

CVSS v3: 9.9 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

connectwise

Products

screenconnect
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute