{"id":23941,"date":"2026-09-17T09:00:00","date_gmt":"2026-09-17T09:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=23941"},"modified":"2026-09-24T09:48:13","modified_gmt":"2026-09-24T09:48:13","slug":"screenconnect-client-executes-files-without-host-approval","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/09\/17\/screenconnect-client-executes-files-without-host-approval\/","title":{"rendered":"ScreenConnect Client Executes Files Without Host Approval"},"content":{"rendered":"<p class=\"evm-ai-translation-notice\" style=\"font-style:italic;color:#868e96;margin:0 0 24px;\">This article is an AI-generated translation of the German original. The German version is authoritative.<\/p>\n<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">4 Min. Read Time<\/p>\n<p><strong>CISA has listed an exploited vulnerability in the ScreenConnect client. During an active remote session, files can be transferred and executed without host confirmation. The deadline for civilian US federal agencies expired on September 14.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"color:#69d8ed;text-transform:uppercase;letter-spacing:0.08em;font-size:0.82em;font-weight:700;margin:0 0 16px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:20px;line-height:1.7;\">\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">CISA lists CVE-2026-84869 as exploited.<\/strong> Civilian US federal agencies had until September 14 to apply patches and conduct forensic reviews.<\/li>\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">ConnectWise limits the flaw to the client.<\/strong> Servers remain unaffected. The severity rating is Important with Priority 1 High and a CVSS score of 9.9.<\/li>\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">Version 26.6.5 fixes the issue.<\/strong> Cloud servers are already updated. Host clients and Access Agents require a fresh installation.<\/li>\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">Huntress observed three incidents in late August.<\/strong> Modified clients pushed files 1.vbs through 4.vbs to newly connected hosts.<\/li>\n<\/ul>\n<\/div>\n<p style=\"border-top:1px solid rgba(230,227,218,0.14);border-bottom:1px solid rgba(230,227,218,0.14);padding:14px 0;margin:28px 0;font-size:0.92em;color:#b8c5ce;\"><strong style=\"color:#69d8ed;\">Related:<\/strong> Attackers Read GitLab Files Without Login \u00b7 Foreign Commands Possible on 8,393 Gitea Servers<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">CISA Gives US Agencies Three-Day Deadline<\/h2>\n<p>The US agency CISA added the vulnerability CVE-2026-84869 to its catalog of known exploited flaws on September 11. The entry concerns ConnectWise ScreenConnect. CISA describes it as a lack of authorization and poor permission management: Files can be transferred and executed during an active remote session without host approval.<\/p>\n<p>Civilian US federal agencies had until September 14 to patch affected systems or implement alternative protections. The catalog also requires forensic analysis. CISA marks Ransomware exploitation as unknown.<\/p>\n<p>The <a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/connectwise-security-advisory-av26-903\">Canadian Cyber Centre<\/a> confirms in advisory AV26-903, updated on September 11, the same inclusion in the catalog of known exploited vulnerabilities. German operators face no comparable deadline, but remain exposed to the same attack.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Files Execute in Session Without Host Approval<\/h2>\n<p><a href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\/2026-09-08-screenconnect-bulletin\">ConnectWise<\/a> described the flaw on September 8, restricting it to the client. Servers remain unaffected.<\/p>\n<p>ConnectWise assigns it a CVSS score of 9.9. The vector includes network-based attacks, low complexity, and low privileges. No host approval is required.<\/p>\n<p>All ScreenConnect versions prior to 26.6.5 are affected. Version 26.6.5 and later resolve the issue. ConnectWise had already warned customers on September 3 about the file transfer behavior and advised removing the TransferFiles permission in open sessions. The patch followed five days later.<\/p>\n<div data-element=\"definition_box\" style=\"background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;padding:20px 24px;margin:32px 0;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);\">\n<p style=\"margin:0 0 8px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Definition \u00b7 ScreenConnect<\/p>\n<p style=\"margin:0;color:#e6e3da;line-height:1.6;\"><strong>What is ScreenConnect?<\/strong> Remote support software from ConnectWise for support and access sessions. Service providers and internal IT teams use it to control remote machines. The cloud version is hosted by ConnectWise, while the on-premise version is self-hosted by the customer. The client on the host executes file transfers and commands.<\/p>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Huntress Identifies Four Scripts Run Through the ScreenConnect Client<\/h2>\n<p><a href=\"https:\/\/www.huntress.com\/blog\/rogue-screenconnect-installations\">Huntress<\/a> observed the same pattern across multiple organizations at the end of August. Rogue clients triggered the Windows Script Host to execute four consecutive VBScript files. The incidents began with social engineering, after which already installed, modified clients automatically pushed the same files to newly connected endpoints. Huntress describes this spread as worm-like.<\/p>\n<p>Two of the documented cases occurred on August 20, and one on August 24. One attack started via Quick Assist, another through a downloaded installer, and a third through a fake refund form.<\/p>\n<p>Huntress labels the files 1.vbs through 4.vbs. In ScreenConnect audit logs, RunFiles or RanFiles with these names executed from the Guest process are flagged as suspicious.<\/p>\n<p>John Hammond, Senior Principal Security Researcher at Huntress, told <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/07\/connectwise-screenconnect-file-transfer-flaw\/\">Help Net Security<\/a> that the observed activity aligns with the vulnerability description. Huntress had previously coordinated its findings with ConnectWise. No specific threat actor group has been identified.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Cloud Update Leaves Host Clients Vulnerable<\/h2>\n<p>ConnectWise has already updated its cloud servers, but the advisory still requires reinstalling host clients and updating access agents. On-premises partners first upgrade to version 26.6.5 and then perform the same client steps. Until then, disabling file transfer permissions in affected sessions reduces the attack surface.<\/p>\n<div style=\"overflow-x:auto;margin:28px 0;\">\n<table style=\"width:100%;min-width:560px;border-collapse:collapse;color:#e6e3da;font-size:0.95em;\">\n<thead>\n<tr>\n<th style=\"background:#003340;color:#69d8ed;text-align:left;padding:10px 12px;border-bottom:1px solid rgba(105,216,237,0.25);\">Deployment<\/th>\n<th style=\"background:#003340;color:#69d8ed;text-align:left;padding:10px 12px;border-bottom:1px solid rgba(105,216,237,0.25);\">Server<\/th>\n<th style=\"background:#003340;color:#69d8ed;text-align:left;padding:10px 12px;border-bottom:1px solid rgba(105,216,237,0.25);\">Clients<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding:10px 12px;border-bottom:1px solid rgba(230,227,218,0.12);\">Cloud<\/td>\n<td style=\"padding:10px 12px;border-bottom:1px solid rgba(230,227,218,0.12);\">ConnectWise has updated<\/td>\n<td style=\"padding:10px 12px;border-bottom:1px solid rgba(230,227,218,0.12);\">Reinstall host clients, update access agents<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:10px 12px;border-bottom:1px solid rgba(230,227,218,0.12);\">On-Premise<\/td>\n<td style=\"padding:10px 12px;border-bottom:1px solid rgba(230,227,218,0.12);\">Upgrade to 26.6.5<\/td>\n<td style=\"padding:10px 12px;border-bottom:1px solid rgba(230,227,218,0.12);\">Perform same client steps after server update<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"margin:12px 0 0;color:#b8c5ce;font-size:0.88em;\">Source: ConnectWise Bulletin on ScreenConnect 26.6.5, dated September 8, 2026.<\/p>\n<\/div>\n<p>The Cybersecurity and Infrastructure Security Agency (CISA) references mandatory action under directive BOD 26-04. However, it remains unclear how many hosts will actually be running the 26.6.5 client by the U.S. deadline of September 14. Server status alone does not answer that question.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Each question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Does this vulnerability affect the ScreenConnect server?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">No. ConnectWise explicitly limits CVE-2026-84869 to the client. Servers remain unaffected. The risk arises during an active support or access session on the host.<\/p>\n<\/details>\n<details>\n<summary><strong>Is the ConnectWise cloud update sufficient?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Yes, for the server. However, the advisory requires reinstalling host clients and updating access agents. Without this step, the vulnerable client remains on the host.<\/p>\n<\/details>\n<details>\n<summary><strong>Which versions address CVE-2026-84869?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">ScreenConnect 26.6.5 and all later versions. All prior versions are affected. ConnectWise released the patch on September 8.<\/p>\n<\/details>\n<details>\n<summary><strong>What did Huntress observe in these incidents?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Three independent cases in late August. Modified clients triggered the Windows Script Host and executed 1.vbs through 4.vbs. The same files spread to newly connected hosts. Huntress does not name the threat actor group.<\/p>\n<\/details>\n<details>\n<summary><strong>Is there a deadline for German operators?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">No German authority deadline exists. CISA granted U.S. civilian agencies until September 14 and additionally requires forensic review. Canada\u2019s Cyber Centre has confirmed the same entry in its catalog.<\/p>\n<\/details>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p>    <span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><br \/>\n        <img decoding=\"async\" alt=\"\" height=\"65\" loading=\"lazy\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/cisa-listet-gitlab-dateien-ohne-login-cover-hero-3-250x143.jpg\" style=\"width:100%;height:100%;object-fit:cover;display:block;\" width=\"116\"\/><br \/>\n    <\/span><br \/>\n    <span style=\"display:block;min-width:0;\"><br \/>\n        <span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor\u2019s Pick<\/span><br \/>\n        <span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Attackers Access GitLab Files Without Login<\/span><br \/>\n    <\/span><\/p>\n<p>    <span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><br \/>\n        <img decoding=\"async\" alt=\"\" height=\"65\" loading=\"lazy\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/cisa-listet-mikrotik-nach-ssh-uebernahmen-cover-hero-1-250x141.jpg\" style=\"width:100%;height:100%;object-fit:cover;display:block;\" width=\"116\"\/><br \/>\n    <\/span><br \/>\n    <span style=\"display:block;min-width:0;\"><br \/>\n        <span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor\u2019s Pick<\/span><br \/>\n        <span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">CISA Sets Deadline: US Agencies Must Patch MikroTik<\/span><br \/>\n    <\/span><\/p>\n<p>    <span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><br \/>\n        <img decoding=\"async\" alt=\"\" height=\"65\" loading=\"lazy\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/08\/gitea-8393-ungepatchte-ips-trotz-juli-fix-cover-hero-250x143.jpg\" style=\"width:100%;height:100%;object-fit:cover;display:block;\" width=\"116\"\/><br \/>\n    <\/span><br \/>\n    <span style=\"display:block;min-width:0;\"><br \/>\n        <span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor\u2019s Pick<\/span><br \/>\n        <span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Remote Commands Possible on 8,393 Gitea Servers<\/span><br \/>\n    <\/span><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/2026\/09\/12\/kubernetes-1-37-haelt-gpu-jobs-nativ-zusammen\/\" style=\"display:flex;align-items:center;margin-bottom:10px;padding:12px 14px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Kubernetes only schedules GPU jobs once all pods fit<\/span><\/span><\/a><br \/>\n<a href=\"https:\/\/mybusinessfuture.com\/bitkom-logistik-kauft-ki-schult-aber-nur-acht-prozent\/\" style=\"display:flex;align-items:center;margin-bottom:10px;padding:12px 14px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#202528;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Skills shortage: Logistics turns to AI instead of training<\/span><\/span><\/a><br \/>\n<a href=\"https:\/\/www.digital-chiefs.de\/oracle-bindet-ki-kapazitaet-ueber-vorauszahlung\/\" style=\"display:flex;align-items:center;padding:12px 14px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#d65663;margin-bottom:5px;\">digital-chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Oracle has customers pre-finance AI expansion<\/span><\/span><\/a><br \/>\n<!--\/ST-LOWER-CARDS--><\/p>\n<p style=\"text-align:right;color:#868e96;font-size:0.75em;margin-top:40px;\"><em>Image source: AI-generated (September 2026)<\/em><\/p>\n<p class=\"evm-ai-translation-notice-end\" style=\"text-align:right;color:#868e96;font-size:0.75em;margin-top:8px;\"><em>Translated from the German original with AI support. The German version is authoritative.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"CISA lists a ScreenConnect client flaw as exploited: files can be transferred and executed without host approval. Version 26.6.5 fixes the issue.","protected":false},"author":10,"featured_media":23768,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"Remote access software","_yoast_wpseo_title":"ScreenConnect Client Executes Files Without Host Approval","_yoast_wpseo_metadesc":"CVE-2026-84869: ScreenConnect clients before version 26.6.5 let files be transferred and executed without host approval during an active remote session.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/screenconnect-client-fuehrt-dateien-ohne-host-ok-aus-cover-hero.jpg","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/screenconnect-client-fuehrt-dateien-ohne-host-ok-aus-cover-hero.jpg","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[254],"tags":[],"class_list":["post-23941","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung"],"evm_reading_time_minutes":6,"wpml_language":"en","wpml_translation_of":23766,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/23941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=23941"}],"version-history":[{"count":4,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/23941\/revisions"}],"predecessor-version":[{"id":23985,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/23941\/revisions\/23985"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/23768"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=23941"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=23941"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=23941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}