Full Report
ConnectWise security advisory (AV26-903)
Analysis Summary
# Vulnerability: ConnectWise ScreenConnect Remote Code Execution
## CVE Details
- **CVE ID:** CVE-2026-84869
- **CVSS Score:** 9.8 (Critical) *(Based on standard ratings for similar RCE flaws in this product line)*
- **CWE:** Not specified in advisory (Likely CWE-287 Authentication Bypass or CWE-434 Unrestricted Upload)
## Affected Systems
- **Products:** ConnectWise ScreenConnect (formerly Control)
- **Versions:** All versions prior to 26.6.5
- **Configurations:** Self-hosted (on-premise) instances are primarily at risk; cloud instances are typically patched automatically by the vendor.
## Vulnerability Description
While the specific technical root cause is not detailed in the summary, CVE-2026-84869 relates to a critical flaw in ScreenConnect that allows an unauthenticated attacker to bypass security restrictions. This type of vulnerability typically permits an attacker to gain administrative access to the ScreenConnect web interface, leading to remote code execution (RCE) on the host server and potentially the ability to push malicious payloads to downstream managed endpoints.
## Exploitation
- **Status:** **Exploited in the wild.** Open-source reporting confirms active targeting by threat actors.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
## Remediation
### Patches
- **ScreenConnect Version 26.6.5:** Users should update to this version immediately. This patch addresses the critical vulnerability identified.
### Workarounds
- **IP Whitelisting:** Restrict access to the ScreenConnect administrative interface (typically ports 8040 and 8041) to known-safe IP addresses.
- **Service Suspension:** If patching cannot be performed immediately, consider taking the ScreenConnect service offline to prevent exploitation.
## Detection
- **Indicators of Compromise:**
- Presence of unfamiliar user accounts with administrative privileges in the ScreenConnect User Management console.
- Unusual extensions or scripts uploaded to the ScreenConnect instance.
- Large volumes of outbound traffic from the ScreenConnect server to unknown external IPs.
- **Detection Methods:**
- Audit `User.xml` for unauthorized account creation.
- Monitor web server logs for unusual POST requests to setup or administration endpoints.
## References
- [ConnectWise Security Bulletin - 2026-09-08] hxxps[://]www[.]connectwise[.]com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin
- [ConnectWise Trust Center] hxxps[://]www[.]connectwise[.]com/company/trust/security-bulletins
- [Cyber Centre Canada Advisory] hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/connectwise-security-advisory-av26-903