CVE-2026-84869
ScreenConnect build distributes a client that can be made to transfer and execute files over an active remote session without Host authorization
- Severity
- critical
- Affected product
- ConnectWise ScreenConnect
- Affected versions
- ConnectWise ScreenConnect < 26.6.5.9742
- Fixed in
- ConnectWise ScreenConnect 26.6.5.9742
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-09-12
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the ConnectWise ScreenConnect appliance and reports this CVE when the detected version falls inside the affected range below.
CISA KEV, added 2026-09-11 (ConnectWise bulletin 2026-09-08). The bug is in the CLIENT, and ConnectWise states the server itself is not exploitable - but the server is what builds and hands out the client, and ConnectWise ships the fix as the server build 26.6.5.9742, so the server version IS the observable that decides whether a deployment is still distributing affected clients. The finding is written as that claim, not as `this server is exploitable`. First 4-part bound in this pack; see the appliances.json note for the version-regex widening it required.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →