CVE-2026-84869CISA KEVEPSS p59.1%

CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise / ScreenConnect

Description

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.

Scoring

CVSS 9.9 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS0.92% probability of exploitation · percentile 59.1% · 2026-10-05T12:00:23Z
Last modified2026-09-12

CISA KEV entry

Added to KEV: 2026-09-11

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.