First published · Last updated
CVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
A vulnerability in ConnectWise ScreenConnect could allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation. The advisory instructs stakeholders to apply vendor mitigations and follow CISA guidance or discontinue use if mitigations are unavailable.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 7/10
- Geographic reach
- 4/10
- Global importance
- 5/10
- Impact magnitude
- 5/10
- Positivity
- 2/10
- Urgency
- 6/10
Why it matters
Stakeholders must apply the listed mitigations and follow CISA BOD 26-04 guidance to reduce risk to affected assets.

