ConnectWise patches a ScreenConnect flaw that let sessions move files

ConnectWise closed a ScreenConnect gap that let live sessions move and run files without consent.

CSBadmin
2 Min Read

Admins running ConnectWise Remote Access have a new build to deploy after the vendor closed a gap that let an operator push files onto a machine and run them mid-session, without the end user ever approving it.

The issue is CVE-2026-84869, and it sits in how support and access sessions handle file transfer. Anyone holding an open session could move and execute code without authorization, a capability uncomfortably close to how remote support tools get turned against the people they are meant to help. The fix landed in ScreenConnect client 26.6.5 and later.

Timing raised eyebrows. Customers got the warning on September 3, with advice to strip the TransferFiles permission from any user holding a live session. Five days passed before a patch appeared.

ConnectWise is still working to rebuild trust after a nation-state intrusion in 2025 that touched several customers. That incident was patched fast, and the company said no one suffered loss.

Remote monitoring and management platforms remain a favorite route for intruders, so the exposure reaches well past a single vendor. Technicians are handed deep access by design. Any gap that skips consent converts a help session into a delivery channel.

Check that clients run 26.6.5 or newer, review who holds file-transfer rights, and turn on consent prompts wherever the product supports them.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.