ConnectWise Patches ScreenConnect Session Vulnerability
ConnectWise has released a security patch for ScreenConnect to resolve a critical vulnerability that allowed unauthorized file transfers and execution during active remote sessions.

ConnectWise has officially released a security update to address a critical authentication vulnerability in its ScreenConnect remote access software. The patch arrives five days after the company first warned its user base about the security flaw, which could allow malicious actors to transfer and execute files through active remote sessions without requiring authorization or confirmation. The vulnerability, tracked as CVE-2026-84869, has been resolved in ScreenConnect client version 26.6.5 and all subsequent releases.
The software provider initially alerted customers to the issue on September 3, specifically highlighting risks associated with support and access sessions within ConnectWise Remote Access. Before the patch was made available, administrators were advised to mitigate the threat manually by logging into the system and removing the "TransferFiles" permission from any users currently engaged in an open session. With the release of version 26.6.5, IT administrators are now urged to update their clients immediately to permanently close this security gap.
For IT practitioners and system administrators, this update is a critical priority to prevent potential remote code execution within managed environments. This incident follows a series of security challenges for ConnectWise, including a "nation-state attack" in May 2025 that impacted several customers, though the company quickly patched that vulnerability and reported no customer losses. Additionally, ConnectWise had to issue emergency patches in 2024 following active exploitation of ScreenConnect, making this latest fix part of an ongoing effort to harden the remote access platform against persistent threats.
This is our own summary of reporting by Computerworld AI


