Published on September 17, 2026 · The mitza.es team

ConnectWise ScreenConnect is one of the most widely used remote-access tools in the world for IT support providers and internal IT teams: it lets a technician connect to a customer's computer to fix issues without having to travel on-site. On September 11, 2026, the US cybersecurity agency CISA added a critical vulnerability in this tool, CVE-2026-84869, to its Known Exploited Vulnerabilities catalog, confirming that real attacks are already taking advantage of it.
What CVE-2026-84869 actually is
The flaw is an improper privilege management and missing authorization issue: it lets an authenticated user with an active remote session transfer and execute arbitrary files on the client machine without needing authorization or host confirmation. In other words, it bypasses exactly the control that's supposed to stop a technician from moving or running files on your computer without your approval. The attack doesn't require any interaction from the victim and is low-complexity.
Timeline: from temporary mitigation to CISA's catalog
- September 7, 2026: ConnectWise publishes a temporary mitigation, recommending disabling the "TransferFiles" permission while the definitive patch is prepared.
- September 11, 2026: CISA adds CVE-2026-84869 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation.
- September 14, 2026: deadline CISA set for US federal agencies to apply the fix, under its binding operational directive BOD 26-04.
- The flaw is fixed in ScreenConnect version 26.6.5 and later.
That specific deadline only applies to US federal agencies, not Spanish businesses, but the level of urgency CISA is treating it with is a clear signal of how serious the flaw actually is.
Why this matters even if you don't use ScreenConnect directly
Most SMEs don't install or manage ScreenConnect themselves: their outside IT support provider uses it to connect to their computers. That means part of your company's security depends on that provider keeping their own tools up to date — something many businesses never actually ask about. It's exactly the kind of supply-chain risk we already covered when discussing NIS2 and supplier security: it's not enough for your own infrastructure to be well protected if the remote-access tool a third party uses to get into it isn't.
Questions worth asking your IT support provider
- Which remote-access tool do you use to connect to our computers?
- If it's ScreenConnect, is it already on version 26.6.5 or later?
- Is file-transfer permission enabled by default, or does it require explicit confirmation each session?
- How do you find out about security advisories like this one, and how quickly do you apply critical patches?
How we see it at Mitza
This case is a good reminder that a company's risk surface doesn't end at its own computers: it also includes the tools its providers use to access them. It's exactly the kind of check included in our IT maintenance service, reviewing what remote-access software is installed and which version it's running, and if you want a broader review of your security and your providers', our audit covers that too. It's another case in the same family as the WordPress vulnerabilities we covered earlier this year: the software you trust to run your business needs active review, not just trust.