ConnectWise patches critical ScreenConnect authentication failure after five days
ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation. The company warned customers on Sept. 3 of the problem with support and access sessions in ConnectWise Remote Access, advising admins to log in and remove the “TransferFiles”…
ConnectWise has released a security update for its ScreenConnect product five days after notifying customers that the software could allow unauthorized file transfer and execution during remote sessions. The issue, affecting support and access sessions within ConnectWise Remote Access, was disclosed on September 3. To mitigate the risk, administrators were advised to log in and remove the "TransferFiles" permission from users with open sessions.
This vulnerability, identified as CVE-2026-84869, has been resolved in ScreenConnect client version 26.6.5 and beyond. In a recent conference, ConnectWise reassured customers following a "nation-state attack" in May 2025, which affected several clients, and promptly released a patch with no reported loss. This incident is not the first for the company; in 2024, a patch was issued after reports of ScreenConnect exploitation.
Written by urgent.news from Computerworld's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.