Executive Summary
In September 2026, CISA added ConnectWise ScreenConnect vulnerability CVE-2026-84869 to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The critical-severity flaw allows attackers with basic privileges to transfer and execute files through active remote sessions without authorization or host confirmation. The vulnerability affects ScreenConnect clients and enables low-complexity attacks requiring no user interaction, prompting CISA to order federal agencies to patch within three days. Over 1,000 vulnerable ScreenConnect instances remain exposed online according to Shadowserver tracking.
This incident highlights the ongoing targeting of remote access tools by both ransomware groups and state-sponsored actors, with ScreenConnect facing its fourth CISA-flagged vulnerability since 2024. The exploitation underscores the critical security risks posed by widely-deployed MSP platforms that provide privileged access to thousands of customer environments.
Why This Matters Now
Remote access tools like ScreenConnect are increasingly targeted as attack vectors into MSP customer networks, with this being the fourth actively exploited ScreenConnect vulnerability flagged by CISA since 2024, demonstrating an accelerating threat landscape.
Attack Path Analysis
Attackers exploited CVE-2026-84869, a critical missing authorization flaw in ScreenConnect, to gain initial access and transfer/execute files without host confirmation. From the compromised remote access session, attackers escalated privileges through the ScreenConnect client, moved laterally across managed systems accessible through the MSP infrastructure, established persistent command and control channels, exfiltrated sensitive data from multiple client environments, and deployed ransomware to encrypt critical systems and demand payment.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-84869 missing authorization vulnerability in unpatched ScreenConnect instances to gain unauthorized file transfer and execution capabilities through active remote sessions
Related CVEs
CVE-2026-84869
CVSS 9.9ConnectWise ScreenConnect contains improper privilege management and missing authorization vulnerability allowing attackers to transfer and execute files through active remote sessions without authorization or host confirmation.
Affected Products:
ConnectWise ScreenConnect – < 26.6.5
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Ingress Tool Transfer
Command and Scripting Interpreter
Valid Accounts
Remote Desktop Protocol
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Privileged Access Management
Control ID: Identity-2
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
PCI DSS 4.0 – Software Security Testing
Control ID: 6.3.3
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical ScreenConnect remote access exploitation enables unauthorized file transfer and execution, compromising managed service operations and client systems through missing authorization vulnerabilities.
Computer/Network Security
Active CVE-2026-84869 exploitation bypasses authorization controls in remote access tools, requiring immediate zero trust segmentation and egress security policy enforcement implementations.
Government Administration
CISA-mandated federal patching within three days reflects severe ransomware risks from ScreenConnect flaws, demanding enhanced threat detection and anomaly response capabilities.
Financial Services
Remote access tool vulnerabilities threaten HIPAA and PCI compliance frameworks, requiring encrypted traffic monitoring and multicloud visibility controls to prevent data exfiltration.
Sources
- Critical ScreenConnect flaw now actively exploited in attackshttps://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-screenconnect-flaw/Verified
- CISA Adds Three Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalogVerified
- ConnectWise ScreenConnect Security Advisoryhttps://www.connectwise.com/company/trust/security-bulletinsVerified
- Shadowserver ScreenConnect Tracking Dashboardhttps://dashboard.shadowserver.org/statistics/iot-devices/time-series/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this ScreenConnect exploitation by constraining lateral movement across MSP client environments and limiting data exfiltration through controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust fabric controls may have constrained the initial ScreenConnect compromise scope by limiting network reachability and reducing the attack surface available to unauthorized remote access attempts
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation policies would likely constrain privilege escalation attempts by limiting workload access scope and reducing the ability to execute unauthorized files across segmented network boundaries
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely reduce lateral movement scope by constraining cross-client environment access and limiting the reachability of systems accessible through the MSP infrastructure
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls may have detected and constrained unauthorized command and control traffic patterns by limiting persistent channel establishment across the compromised ScreenConnect infrastructure
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely constrain data exfiltration scope by limiting unauthorized outbound data transfers and reducing the volume of sensitive information accessible for extraction
While ransomware deployment may still occur, the constrained lateral movement and reduced blast radius would likely limit the scope of encryption to fewer client systems and environments
Impact at a Glance
Affected Business Functions
- Remote IT Support Services
- System Administration
- Technical Help Desk
- Managed Service Provider Operations
Estimated downtime: 3 days
Estimated loss: N/A
Unauthorized file access and execution capabilities on client systems managed through ScreenConnect remote sessions, potentially exposing sensitive business data, configuration files, and system credentials across managed service provider client environments.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate remote access tools like ScreenConnect from critical production systems and limit blast radius of compromise
- • Deploy Multicloud Visibility & Control to detect anomalous interactions and repeated malformed requests that could indicate exploit attempts against remote access platforms
- • Establish Egress Security & Policy Enforcement to prevent unauthorized data exfiltration through compromised remote access channels and block connections to unauthorized destinations
- • Utilize Inline IPS (Suricata) to detect and block known exploit patterns targeting CVEs like CVE-2026-84869 before they reach vulnerable applications
- • Enable Threat Detection & Anomaly Response capabilities to baseline normal remote access tool behavior and alert on suspicious file transfers or unauthorized execution activities



