bleeping-computer · Crawled Sep 16, 2026

Critical ScreenConnect flaw now actively exploited in attacks

1 Actors
Read original article ↗

AI Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of active exploitation of a critical-severity vulnerability in ConnectWise ScreenConnect, tracked as CVE-2026-84869. The flaw, which stems from improper privilege management and missing authorization, allows attackers with basic privileges to transfer or execute files during active remote sessions without requiring user interaction. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies to remediate it within three days. Over 1,000 unpatched instances remain exposed globally, primarily in North America and Europe, posing significant risks to federal and enterprise networks.

AI-extracted · verify before operational use

Extracted Entities 1 found

MITRE ATT&CK TTPs 8 techniques