# CVE-2026-84869

## Summary

- **CVE ID:** CVE-2026-84869
- **Severity:** CRITICAL
- **CVSS Score:** 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-862, CWE-269
- **Published:** Sep 8, 2026
- **Last Modified:** Sep 9, 2026

## Description

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

## Affected Products

- ConnectWise — ScreenConnect (All versions prior to 26.6.5)

## References

- [CNA](https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin)
- [CNA](https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-84869)
- [CNA](https://www.connectwise.com/company/trust/advisories)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.38%
- **EPSS Percentile:** 31.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._