THREAT BRIEFING · 08.10.2026 DEENFRES

Practice & Implementation

ScreenConnect Client Executes Files Without Host Approval

By Alec Chizhik · September 17, 2026 · 6 min read

This article is an AI-generated translation of the German original. The German version is authoritative.

4 Min. Read Time

CISA has listed an exploited vulnerability in the ScreenConnect client. During an active remote session, files can be transferred and executed without host confirmation. The deadline for civilian US federal agencies expired on September 14.

Key Takeaways

  • CISA lists CVE-2026-84869 as exploited. Civilian US federal agencies had until September 14 to apply patches and conduct forensic reviews.
  • ConnectWise limits the flaw to the client. Servers remain unaffected. The severity rating is Important with Priority 1 High and a CVSS score of 9.9.
  • Version 26.6.5 fixes the issue. Cloud servers are already updated. Host clients and Access Agents require a fresh installation.
  • Huntress observed three incidents in late August. Modified clients pushed files 1.vbs through 4.vbs to newly connected hosts.

Related: Attackers Read GitLab Files Without Login · Foreign Commands Possible on 8,393 Gitea Servers

CISA Gives US Agencies Three-Day Deadline

The US agency CISA added the vulnerability CVE-2026-84869 to its catalog of known exploited flaws on September 11. The entry concerns ConnectWise ScreenConnect. CISA describes it as a lack of authorization and poor permission management: Files can be transferred and executed during an active remote session without host approval.

Civilian US federal agencies had until September 14 to patch affected systems or implement alternative protections. The catalog also requires forensic analysis. CISA marks Ransomware exploitation as unknown.

The Canadian Cyber Centre confirms in advisory AV26-903, updated on September 11, the same inclusion in the catalog of known exploited vulnerabilities. German operators face no comparable deadline, but remain exposed to the same attack.

Files Execute in Session Without Host Approval

ConnectWise described the flaw on September 8, restricting it to the client. Servers remain unaffected.

ConnectWise assigns it a CVSS score of 9.9. The vector includes network-based attacks, low complexity, and low privileges. No host approval is required.

All ScreenConnect versions prior to 26.6.5 are affected. Version 26.6.5 and later resolve the issue. ConnectWise had already warned customers on September 3 about the file transfer behavior and advised removing the TransferFiles permission in open sessions. The patch followed five days later.

Definition · ScreenConnect

What is ScreenConnect? Remote support software from ConnectWise for support and access sessions. Service providers and internal IT teams use it to control remote machines. The cloud version is hosted by ConnectWise, while the on-premise version is self-hosted by the customer. The client on the host executes file transfers and commands.

Huntress Identifies Four Scripts Run Through the ScreenConnect Client

Huntress observed the same pattern across multiple organizations at the end of August. Rogue clients triggered the Windows Script Host to execute four consecutive VBScript files. The incidents began with social engineering, after which already installed, modified clients automatically pushed the same files to newly connected endpoints. Huntress describes this spread as worm-like.

Two of the documented cases occurred on August 20, and one on August 24. One attack started via Quick Assist, another through a downloaded installer, and a third through a fake refund form.

Huntress labels the files 1.vbs through 4.vbs. In ScreenConnect audit logs, RunFiles or RanFiles with these names executed from the Guest process are flagged as suspicious.

John Hammond, Senior Principal Security Researcher at Huntress, told Help Net Security that the observed activity aligns with the vulnerability description. Huntress had previously coordinated its findings with ConnectWise. No specific threat actor group has been identified.

Cloud Update Leaves Host Clients Vulnerable

ConnectWise has already updated its cloud servers, but the advisory still requires reinstalling host clients and updating access agents. On-premises partners first upgrade to version 26.6.5 and then perform the same client steps. Until then, disabling file transfer permissions in affected sessions reduces the attack surface.

Deployment Server Clients
Cloud ConnectWise has updated Reinstall host clients, update access agents
On-Premise Upgrade to 26.6.5 Perform same client steps after server update

Source: ConnectWise Bulletin on ScreenConnect 26.6.5, dated September 8, 2026.

The Cybersecurity and Infrastructure Security Agency (CISA) references mandatory action under directive BOD 26-04. However, it remains unclear how many hosts will actually be running the 26.6.5 client by the U.S. deadline of September 14. Server status alone does not answer that question.

Frequently Asked Questions

Each question is locked. A tap unlocks the answer.

Does this vulnerability affect the ScreenConnect server?

No. ConnectWise explicitly limits CVE-2026-84869 to the client. Servers remain unaffected. The risk arises during an active support or access session on the host.

Is the ConnectWise cloud update sufficient?

Yes, for the server. However, the advisory requires reinstalling host clients and updating access agents. Without this step, the vulnerable client remains on the host.

Which versions address CVE-2026-84869?

ScreenConnect 26.6.5 and all later versions. All prior versions are affected. ConnectWise released the patch on September 8.

What did Huntress observe in these incidents?

Three independent cases in late August. Modified clients triggered the Windows Script Host and executed 1.vbs through 4.vbs. The same files spread to newly connected hosts. Huntress does not name the threat actor group.

Is there a deadline for German operators?

No German authority deadline exists. CISA granted U.S. civilian agencies until September 14 and additionally requires forensic review. Canada’s Cyber Centre has confirmed the same entry in its catalog.

Editor’s Picks





Editor’s Pick
Attackers Access GitLab Files Without Login





Editor’s Pick
CISA Sets Deadline: US Agencies Must Patch MikroTik





Editor’s Pick
Remote Commands Possible on 8,393 Gitea Servers

More from the MBF Media Network

cloudmagazinKubernetes only schedules GPU jobs once all pods fit
MyBusinessFutureSkills shortage: Logistics turns to AI instead of training
digital-chiefsOracle has customers pre-finance AI expansion

Image source: AI-generated (September 2026)

Translated from the German original using artificial intelligence. The German version is authoritative.

Further reading

A magazine by Evernine Media GmbH