Search
Find merged stories by title or summary.
ConnectWise patches critical ScreenConnect authentication failure after five days
ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation. The company warned customers on Sept. 3 of the problem with support and access sessions in ConnectWise Remote Access, advising admins to log in and remove the “TransferFiles” permission from any users with an open session. The vulnerability, tracked as CVE-2026-84869 , has been patched in the ScreenConnect client version 26. 6. 5 onwards. Last month ConnectWise took the opportunity to reassure customers at its IT Nation Connect Asia Pacific conference that it was getting back on track after a “nation-state attack” in May 2025 that had affected several customers. The company quickly released a patch for that attack and said no customers had suffered loss.
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability • CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability • CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
[CISA] CVE-2026-84869 - Confirmed Exploitation
CVE-2026-84869 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-09-11 00:00 UTC Evidence Sources: 1 First Seen: 2026-09-11 Asserted: 2026-09-11
CVE-2026-84869 Detail - nvd.nist.gov
CVE-2026-84869 Detail nvd. nist. gov
You've reached the end of current stories for this search.
