Attackers are exploiting a critical ConnectWise ScreenConnect vulnerability in the wild, prompting CISA to add it to its actively exploited catalog and order federal agencies to secure systems quickly. The flaw, tracked as CVE-2026-84869, can let attackers with basic privileges transfer or execute files, and more than 1,000 exposed instances remain unpatched online. #ConnectWise #ScreenConnect #CVE-2026-84869 #CISA #Shadowserver
Keypoints
- CISA says CVE-2026-84869 is being exploited in the wild.
- The flaw affects ConnectWise ScreenConnect clients and enables file transfer or execution.
- ConnectWise advised disabling TransferFiles permissions as a temporary mitigation.
- CISA ordered U.S. federal agencies to address the issue within three days.
- Shadowserver reports more than 1,000 exposed ScreenConnect instances still unpatched.