ConnectWise patches critical ScreenConnect authentication failure after five days

4 hours ago 3

if ( !emtpy($headline_subheadline ) ) : ?>

The company seeks to reassure users after revealing a new vulnerability.

endif; ?>

ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation.

The company warned customers on Sept. 3 of the problem with support and access sessions in ConnectWise Remote Access, advising admins to log in and remove the “TransferFiles” permission from any users with an open session.

The vulnerability, tracked as CVE-2026-84869, has been patched in the ScreenConnect client version 26.6.5 onwards.

Read Entire Article