CVE-2026-84869: Critical ScreenConnect Client Flaw Under Active Exploitation

Red | Vulerability
CVE-2026-84869: Critical ScreenConnect Client Flaw Under Active Exploitation

First Seen: August 20, 2026

Malware: XMRig cryptominer

Affected Product: ConnectWise ScreenConnect client

Impact: ConnectWise ScreenConnect, a remote support and access platform widely used by MSPs and IT teams, is affected by a critical client-side vulnerability (CVE-2026-84869) in which missing authorization and improper privilege management in file-transfer handling allow a Guest in an active session to transfer and execute files on the Host without confirmation; servers are unaffected, but all clients prior to 26.6.5 are vulnerable and must be reinstalled or redeployed. Exploitation has been observed in an unattributed campaign since late August 2026, where socially engineered rogue clients executed a four-stage VBScript loader and backdoored clients pushed the same chain to every newly connected Host, producing worm-like spread. Payloads included a hidden ScreenConnect backdoor, UAC and Defender bypasses, a vulnerable WinRing0 driver, tunnelling and an XMRig miner, giving attackers persistent code execution on technician hosts and a pivot into downstream client networks.

CVE

CVENameAffected ProductZero-DayCISA KEVPatch
CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization VulnerabilityConnectWise ScreenConnectNoNoYes

Vulnerability Details

#1
ConnectWise ScreenConnect is a remote support and access platform used extensively by managed service providers and IT teams for remote assistance and unattended endpoint access. It is affected by a critical vulnerability tracked as CVE-2026-84869, arising from improper privilege management and missing authorization in the client’s file-transfer handling during active Support and Access sessions. Under certain conditions, a Guest-side participant in an established session can transfer files to the Host and trigger their execution, including via elevated execution paths, without the authorization check or Host confirmation the product is designed to enforce. The weakness resides in the client and session-handling components; servers are not affected. All client builds prior to version 26.6.5 are vulnerable, and because the flaw is client-side, upgrading the server alone is insufficient — Host clients and Access agents must be reinstalled or redeployed afterwards.
#2
Exploitation activity consistent with the flaw has been observed in an unattributed campaign active since late August 2026. Initial access relied on social engineering rather than server compromise: tech-support scams abusing Quick Assist, a likely phishing-delivered installer, and a fake refund-form lure led victims to run rogue ScreenConnect clients pointing at attacker-controlled infrastructure. The clients spawned Windows Script Host to execute a four-stage VBScript loader that profiled the system, enumerated endpoint security products, checked available RAM as a likely virtual-machine test, and retrieved AES-encrypted payloads from cloud storage. Backdoored clients monitored for newly established Host connections and automatically queued the same script chain for transfer and execution with a Run action, producing worm-like propagation over legitimate support sessions and re-triggering on reconnection.
#3
Successful exploitation yields arbitrary code execution on the connecting Host. Depending on host profile, observed payloads delivered a user-level ScreenConnect backdoor; a UAC bypass with AMSI and Defender evasion and a concealed persistent client; or encrypted tunnelling, a vulnerable WinRing0 driver and an XMRig miner, with persistence via a WindowsServiceHost Run key and secondary RMM tools such as UltraViewer. For MSPs the impact is severe: an infected technician Host becomes a delivery mechanism into every downstream network it touches, and affected hosts should be reimaged rather than cleaned in place.

Vulnerability

CVE IDAffected ProductsAffected CPECWE ID
CVE-2026-84869ConnectWise ScreenConnect client version before 26.6.5cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:*CWE-269, CWE-862

Recommendations

01
Upgrade All ScreenConnect Clients to 26.6.5 or Later Immediately

Version 26.6.5 contains the vendor fix and is the only complete remediation. On-premises servers must be running version 25.4 or later before moving to 26.6.5. Cloud instances receive the update automatically, but administrators must still refresh or remove and redeploy host clients and agents after the upgrade.

02
Hunt for Exploitation Artefacts Before Declaring Systems Clean

Review ScreenConnect server audit logs for RunFiles or RanFiles entries executed from Process: Guest referencing 1.vbs through 4.vbs or WindowsServiceHost.vbs. Inspect endpoints for ScreenConnect.WindowsClient.exe spawning wscript.exe, the WindowsServiceHost Run key, and the malicious ScreenConnect instance ID 7a4d7d66502d4260. Hosts showing this activity should be reimaged from known-good media.

03
Apply Temporary Workarounds Where Patching Is Delayed

Remove or disable the TransferFiles permission (TransferFilesInSession in legacy versions) from all roles to block in-session file transfer and remote execute features — the vendor’s interim guidance from September 3. Enforce session policies requiring explicit Host confirmation and constrain child processes spawned by ScreenConnect client binaries.

04
Run a Credential Hygiene Campaign

Because the flaw is exploited through sessions the system already trusts, reset administrator and privileged user passwords, enforce multi-factor authentication on all ScreenConnect accounts, and validate every user and agent account against an approved inventory.

05
Reduce the Attack Surface of the ScreenConnect Deployment

Restrict web interface and relay access to trusted IP ranges, place ScreenConnect behind a VPN or on internal networks where possible, segregate instances from sensitive network segments, enforce SSL/TLS, and apply least privilege to all roles.


Potential MITRE ATT&CK TTPs

Initial Access
T1566: Phishing
Execution
T1059: Command and Scripting Interpreter → T1059.005 Visual Basic, T1059.001 PowerShell
T1204: User Execution → T1204.002 Malicious File
Persistence
T1547: Boot or Logon Autostart Execution → T1547.001 Registry Run Keys / Startup Folder
T1543: Create or Modify System Process → T1543.003 Windows Service
T1219: Remote Access Software
Privilege Escalation
T1548: Abuse Elevation Control Mechanism → T1548.002 Bypass User Account Control
T1068: Exploitation for Privilege Escalation
Defense Evasion
T1562: Impair Defenses → T1562.001 Disable or Modify Tools
T1036: Masquerading → T1036.005 Match Legitimate Name or Location
T1027: Obfuscated Files or Information
T1070: Indicator Removal → T1070.004 File Deletion
T1497: Virtualization/Sandbox Evasion → T1497.001 System Checks
T1564: Hide Artifacts
Discovery
T1518: Software Discovery → T1518.001 Security Software Discovery
T1082: System Information Discovery
Lateral Movement
T1570: Lateral Tool Transfer
Command and Control
T1105: Ingress Tool Transfer
T1102: Web Service
T1071: Application Layer Protocol → T1071.001 Web Protocols
T1572: Protocol Tunneling
Impact
T1496: Resource Hijacking → T1496.001 Compute Hijacking

Indicators of Compromise (IOCs)

TypeValue
SHA25608bc4e82883eb42fc5219b206555b7a02a879860c76b4a12b2f82a64f6cc9020,
de3b6836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457,
19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117f3260,
110fffc85370bb7cc60fa023447165c7e99175473d76bc5ffb2abecaa3a41d66,
de89d560fc8302c778d88e3938327b240fa0db9a64fc1d5643067eedcbd2aede,
ffd6d23f579571cc61936145791975da78b6ae914d780a9447a8f53c3688a0de
IPv445[.]13[.]237[.]190, 146[.]59[.]55[.]107, 45[.]32[.]192[.]150, 15[.]204[.]185[.]204
IPv4:Port131[.]123[.]40[.]98[:]8041
Domainstele-sync[.]opik[.]net, borertors92[.]anondns[.]net, homehub[.]opik[.]net
Filename1.vbs, 2.vbs, 3.vbs, 4.vbs, WindowsServiceHost.vbs, WindowsServiceHost.bat, value.txt, map.txt, out.tmp, out.enc, user.enc, acc.enc, combo.enc, runner.ps1, PyTorchFix.ps1, Password.exe, sys_cache.zip, Themes.exe, SearchIndex.exe, svcdrv64.sys
File Path%TEMP%\value.txt, %TEMP%\map.txt, %TEMP%\out.enc, %TEMP%\runner.ps1, %APPDATA%\Microsoft\Windows\Templates\Classic\sys_cache.zip, C:\Users\Public\Libraries\Default\Lib\Lib1
Registry KeyHKCU\Software\Microsoft\Windows\CurrentVersion\Run → WindowsServiceHost
ScreenConnect Instance ID7a4d7d66502d4260
Detection NameTrojan:Script/Wacatac.H!ml

Patch Links


References

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Reduce real exposure. Not just vulnerability volume.