CVE-2026-84869

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

  • Published Sep 8, 2026
  • CVSS 9.9 critical
  • 0.9% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog

Affected software

CVE-2026-84869 at the National Vulnerability Database