← All CVEs NewScan detects
criticalKEV

CVE-2026-84869

ScreenConnect build distributes a client that can be made to transfer and execute files over an active remote session without Host authorization

Severity
critical
Affected product
ConnectWise ScreenConnect
Affected versions
ConnectWise ScreenConnect < 26.6.5.9742
Fixed in
ConnectWise ScreenConnect 26.6.5.9742
CISA KEV
Listed as a known exploited vulnerability
Added to NewScan
2026-09-12
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the ConnectWise ScreenConnect appliance and reports this CVE when the detected version falls inside the affected range below.

CISA KEV, added 2026-09-11 (ConnectWise bulletin 2026-09-08). The bug is in the CLIENT, and ConnectWise states the server itself is not exploitable - but the server is what builds and hands out the client, and ConnectWise ships the fix as the server build 26.6.5.9742, so the server version IS the observable that decides whether a deployment is still distributing affected clients. The finding is written as that claim, not as `this server is exploitable`. First 4-part bound in this pack; see the appliances.json note for the version-regex widening it required.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →