CISA gives agencies three days to patch ScreenConnect

Published

CISA added a critical ConnectWise ScreenConnect flaw to its Known Exploited Vulnerabilities catalog on September 11 and gave federal agencies until September 14 to deal with it. Three days is a short fuse even by KEV standards. The reason is in the listing itself: the catalog only accepts vulnerabilities with evidence of active exploitation.

The bug is CVE-2026-84869. In the National Vulnerability Database's wording, a condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or host confirmation in certain circumstances. ScreenConnect servers are not affected. Every client version before 26.6.5 is.

What the record actually says

It carries a CVSS v3.1 base score of 9.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) and two weakness classes, improper privilege management and missing authorization. CISA's own decision record for the entry marks exploitation as active and the technical impact as total, while rating it not automatable, meaning this is not something an attacker can spray at the internet.

The EPSS model, which predicts exploitation activity over the next 30 days, puts it at 0.4%, around the 32nd percentile. That is worth stating plainly rather than quietly dropping, because it looks like a contradiction and is not one. EPSS is a forecast; a KEV entry is an observation. When a forecast and an observation disagree, the observation wins.

Beyond that, the public record is thin. Neither the CISA alert nor the NVD entry explains how the condition is reached or what access an attacker needs first, and we are not going to guess at it. ConnectWise's security bulletin of September 8 and its published disclosure notes are where any detail will be.

A bad product to leave sitting unpatched

ScreenConnect is remote support software. It is installed precisely so that somebody far away can put files on a machine and run them, which is also why it is one of the most consistently abused remote management tools in criminal hands. Attackers routinely install it themselves as a quiet backdoor, as in the campaign where fake software download sites shipped it alongside AsyncRAT. A flaw in the file transfer and execution path that skips host confirmation removes the one step a watching user could have refused.

Move clients to 26.6.5

The fix is to update clients to version 26.6.5 or later. Because the flaw sits in the client rather than the server, a patched server does not protect endpoints still running an old agent, so the inventory that matters here is the agent estate, including machines a managed service provider installed years ago and nobody has thought about since. Federal civilian agencies are bound by BOD 26-04 and the September 14 date. Everyone else should read the KEV entry as the signal it was designed to be.

It was not the only item on the list that day. CISA added three vulnerabilities in that batch and one in a separate notice, and we have already covered the other two products: attackers turning unauthenticated requests into JFrog Artifactory administrator accounts, and unpatched GitLab servers handing files to anyone who asks for them. The original notice is CISA's alert of September 11.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Detection coverage

Read the full analysis on IntelFusions