ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation.
The company warned customers on Sept. 3 of the problem with support and access sessions in ConnectWise Remote Access, advising admins to log in and remove the “TransferFiles” permission from any users with an open session.
The vulnerability, tracked as CVE-2026-84869, has been patched in the ScreenConnect client version 26.6.5 onwards.
Last month ConnectWise took the opportunity to reassure customers at its IT Nation Connect Asia Pacific conference that it was getting back on track after a “nation-state attack” in May 2025 that had affected several customers. The company quickly released a patch for that attack and said no customers had suffered loss.
This was not the first time that the company had suffered from a cyberattack. In 2024, ConnectWise had to issue a patch after reports that ScreenConnect had been exploited.
This story first appeared on Computerworld.
No Responses