Key Facts
CISA added CVE-2026-84869 to its Known Exploited Vulnerabilities Catalog on September 11, 2026. The catalog identifies ConnectWise ScreenConnect as the affected product.
Technical Details
CISA describes CVE-2026-84869 as improper privilege management and missing authorization. Its description says the issue may allow file transfer and execution through active remote sessions without authorization or host confirmation.
Impact & Mitigation
Apply ConnectWise’s mitigations and update ScreenConnect. CISA sets September 14, 2026 as the remediation due date for U.S. federal civilian executive-branch agencies; other organizations should prioritize exposed and high-value remote-support deployments.
