DEV Community

Cover image for ConnectWise Patches Critical ScreenConnect Flaw Exploited in Worm Attacks
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

ConnectWise Patches Critical ScreenConnect Flaw Exploited in Worm Attacks

Summary

ConnectWise fixed a critical vulnerability (CVE-2026-84869) in ScreenConnect that allows unauthorized file execution and worm-like propagation across remote sessions.

Take Action:

If you use ConnectWise ScreenConnect, update to version 26.6.5 right away and then reinstall every host client. The update only takes effect once the clients are reinstalled, and this flaw is already being exploited to spread from machine to machine. If you can't patch, turn off the TransferFiles permission for all user roles as a mitigating measures. Don't forget to check integrated tools like ConnectWise Automate for their own patched versions.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)