CISA has added a critical ScreenConnect vulnerability, now designated CVE-2026-84869, to its known exploited vulnerabilities catalog after confirming attackers are actively abusing it. The flaw stems from missing authorization checks that let low-privilege users transfer and execute files during active remote sessions without host confirmation, and it has been fixed in ScreenConnect 26.6.5. Federal agencies have been given three days to patch, while Shadowserver reports over 1,000 unpatched, internet-exposed ScreenConnect servers, mostly in North America and Europe.
bleepingcomputer.com
· 2026-09-16
Attackers are exploiting a chain of legitimate Google services, including redirect links, to disguise malicious URLs and slip past email security filters. Victims who follow the multi-hop links are directed either to credential-harvesting phishing pages or prompted to install ScreenConnect remote access software.
darkreading.com
· 2026-09-08
ConnectWise disclosed a new security flaw in its ScreenConnect remote access platform affecting file transfer behavior in both cloud and on-premises deployments. The vulnerability has no CVE identifier yet and no official patch, though the company says a fix is coming later this week. In the meantime, ConnectWise published manual mitigation steps requiring administrators to disable file transfer permissions across user roles.
bleepingcomputer.com
· 2026-09-07
Huntress researchers found phishing campaigns that trick victims into running a disguised but legitimate Faronics Deploy installer, often labeled as an Adobe file, which secretly enrolls their machine into an attacker-controlled management console. From there, attackers run PowerShell scripts to fetch additional tools and install ConnectWise ScreenConnect, giving them persistent remote access. Over 457 endpoints were targeted between July 21 and August 20 using fake invoice and tax-document lures.
bleepingcomputer.com
· 2026-09-01