ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
Vulnerabilities
The flaw allows attackers to send files and execute them without authorization through an active remote session.
ConnectWise has released urgent patches for a critical-severity vulnerability in the ScreenConnect remote access and support software that has been exploited in worm-like attacks.
Tracked as CVE-2026-84869 (CVSS score of 9.9/10), the security defect is described as a missing authorization and improper privilege management issue.
The bug creates “a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances,” ConnectWise explains in its advisory.
In early September, cybersecurity firm Huntress warned that the vulnerability has been exploited in the wild since August 20.
As part of the observed incidents, a modified ScreenConnect instance was used to deploy four VBScript files designed to establish persistence and propagate to other ScreenConnect clients.
The hackers used social...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE