ConnectWise

ScreenConnect 26.6.5 Security Patch

Date: 09/08/2026
Product(s): ConnectWise ScreenConnect
Severity: Important
Priority: 1 - High

Summary
ConnectWise has released a security update for ScreenConnect™ that addresses a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted. The ScreenConnect 26.6.5 patch includes updates to strengthen client and session handling for file-transfer and file-execution actions.

Vulnerability

CVE-2026-84869

CWE ID Description Base Score Vector
CWE-862 Missing Authorization 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-269 Improper Privilege
Management

 

Severity
Important—Vulnerabilities that could compromise confidential data or other resources but require additional access, privilege or circumstances to do so.

 

Priority
1 High—Vulnerabilities that are either being targeted or have higher risk of being targeted by exploits in the wild. Recommend installing updates as emergency changes or as soon as possible (e.g., within days).

 

Affected versions
ScreenConnect version prior to 26.6.5 are impacted.

 

Remediation

Cloud

On-premise

ScreenConnect Partners:

Please upgrade to ScreenConnect version 26.6.5. Visit Download | ScreenConnect page to download and apply the update (access requires a valid on-premises license).

  • If your license is out of maintenance, you must upgrade your license before installing the latest supported release of ScreenConnect.
  • If you are unable to apply the update immediately due to maintenance windows or change-freeze policies, you can implement the following as a temporary mitigation to help reduce exposure until the update can be applied. This is not a substitute for installing the security update.
  1. Navigate to the Administration > Security > Roles section.
  2. Edit a role, review each session group that has permissions assigned to it, and deselect the TransferFiles permission if it is selected. Save your changes.
  3. Repeat for each role.

Automate On-Prem Partners with ScreenConnect Integration:
Automate partners are eligible to update their integrated on-premises ScreenConnect installation as long as their Automate Assurance subscription is active. For partners using an on-premises ScreenConnect installation integrated with Automate, ScreenConnect 26.6.5 is available through the Automate Product Updates page.

Link to release notes: ScreenConnect 26.6 release notes

 

FAQs

Where can I get more information about the vulnerability?

All information about the vulnerability is posted on the ConnectWise Trust site: https://www.connectwise.com/company/trust/security-bulletins. Because of the sensitive nature of this vulnerability, we are not able to provide any more details or information.

What should I do if I think my instance has been compromised?

If you suspect that your ScreenConnect software may have been compromised, it is crucial to prioritize the security of your systems. Follow your established incident response procedures to isolate the affected servers and create backups for later analysis. Do not bring these servers back online until they have been thoroughly investigated, rebuilt, and updated with the latest patches.

Keep in mind that a compromised ScreenConnect server may not be the sole point of entry. Your incident response plan should cover your entire system to detect and address any broader security vulnerabilities.

If you have concerns about a potential compromise, please refer to the steps outlined in this Security alert checklist which includes actions such as resetting their passwords, reviewing the audit log, forcing all technicians to sign back in, and more. We also recommend reviewing the ScreenConnect security guide and best practices to enhance the security of your instance, as well as verifying that links, your account ID, and your domain are accurate.

Where do I download new versions of ScreenConnect? 

Cloud instances are upgraded to new versions of ScreenConnect automatically.

For on-premises users, new versions of ScreenConnect can be downloaded from the ScreenConnect website: (access requires a valid on-premises license). Download | ScreenConnect

If your renewal is due in 2026, you are eligible to upgrade to 26.6 without renewing your license. Be sure to check your “Latest Eligible Version” on the Administration > Overview page to confirm your eligibility for 26.6.5

What happens once I patch ScreenConnect to a remediated version?

Once you’ve applied the patch, you should review users with access to ScreenConnect, including but not limited to: reviewing users and removing any that are not recognized, reviewing users’ roles and permissions, changing passwords, and enabling MFA.

How do I migrate to cloud from On-Premises?

We have instructions in our documentation: Migrate to ScreenConnect Cloud from a Windows server - ConnectWise

How do I upgrade my server?

Cloud instances have already been updated to version 26.6.5. Partners can verify their current version on the Administration > Overview page of their instance.

You can upgrade your on-premises server by following the instructions here: Upgrade to the latest version of ScreenConnect.

What is the upgrade path for an on-premises server?

On‑premises partners must be running ScreenConnect version 25.4 or later to upgrade to version 26.6.5. Partners should verify their current version and upgrade eligibility on the Administration > Overview page.

For detailed upgrade instructions and supported upgrade paths, refer to the official documentation here: Upgrade an on-premises installation - ConnectWise

What is the “eligible version”?

The eligible version is the latest ScreenConnect version supported by your current license. Before upgrading to ScreenConnect 26.6.5, partners should review the Administration > Overview page to confirm that 26.6.5 is an eligible version for your current license.

Is there a mitigation?

If you are unable to apply the update immediately due to maintenance windows or change-freeze policies, deselecting the TransferFiles permission (previously named TransferFilesInSession) for all user roles may reduce exposure until the update is applied:

  1. Navigate to the Administration > Security > Roles section.
  2. Edit a role, review each session group that has permissions assigned to it, and deselect the TransferFiles permission if it is selected.
  3. Save your changes. Repeat for each role.

How do I ensure I’m notified of updates?

To ensure you’re contacted about important security updates, please set rules that allow ConnectWise communication to hit your primary inbox – add no-reply@connectwise.com to your safe sender list to ensure these important communications are delivered to your inbox. 

To receive security bulletins as they’re posted, we also recommend using the ConnectWise Trust RSS feed. 

How do you determine the priority and severity of bulletins?

We use the following criteria to assign priority and severity to each bulletin.

Severity
Rating Definition
Critical Vulnerabilities that could allow the ability to execute remote code or directly impact confidential data or critical systems.
Important Vulnerabilities that could compromise confidential data or other resources but require additional access, privilege or circumstances to do so.
Moderate Vulnerabilities where impact is limited to a significant degree by mitigating factors such as version / configuration, detective controls, or are otherwise difficult to exploit.
Priority
Rating Label Definition
1 High Vulnerabilities that are either being targeted or have higher risk of being targeted by exploits in the wild. Recommend installing updates as emergency changes or as soon as possible (e.g., within days).
2 Moderate Vulnerabilities that have elevated risk but exploits are neither known nor anticipated to be imminent. Recommend updates be prioritized against normal change management timelines but no longer than 30 days.
3 Low Vulnerabilities that have historically not been targeted. Updates discretionary.

Why didn’t I receive an email?  Who at my company did receive an email?

To help ensure you receive future communications from ConnectWise add no-reply@connectwise.com to your safe sender list to ensure these important communications are delivered to your inbox.

In addition, please update your primary contact details by reaching out to your dedicated account manager. You can also ensure your email preferences are correctly configured in our online self-service ConnectWise Profile and Preference Center.

To ensure you receive the latest security-related communications from ConnectWise, we highly recommend subscribing to the RSS feeds from our Trust Center to ensure you receive real-time notifications on the latest security advisories and bulletins.

If you have confirmed that your primary contact information is accurate and you are still not receiving emails from our system, we kindly request that you share the primary contact email with us for further investigation.

How do I report a security incident?

If you have questions or need to report a security or privacy incident, please visit our ConnectWise Trust Center. You can also call our Partner InfoSec Hotline at 1-888-WISE911 to report a non-active security incident or a security vulnerability.

Where can partners go for more information and support?

We are communicating in many platforms to make sure you stay informed. However, our FAQ page will capture the latest questions that are frequently asked as this evolves. We also encourage to go online to our Trust Center for the latest advisories and bulletins for more information. For real-time updates, we recommend subscribing to the ConnectWise security bulletin RSS feed.

If you do not find what you are looking for here and you need additional assistance or have more questions, please go online to ConnectWise Home and open a case with our support team or email help@connectwise.com.