ConnectWise’s Sep 8 bulletin patches CVE-2026-84869 — a client-side missing-authorization / improper privilege-management issue rated CVSS 9.9. In certain circumstances, files can be transferred and executed through an active remote session without authorization or Host confirmation. ScreenConnect servers are not impacted. Versions prior to 26.6.5 are affected. Cloud instances were upgraded by the vendor; on-prem partners must upgrade, then reinstall host clients and update access agents. Interim mitigation only: deselect TransferFiles (legacy TransferFilesInSession) on all roles — not a substitute for the patch.
Huntress documented worm-like behavior across unrelated orgs: rogue ScreenConnect clients (often after social engineering / Quick Assist) spawning wscript.exe to run a four-stage VBScript chain (1.vbs–4.vbs), with modified clients packaging those scripts into file-transfer “Run” messages for newly connected Host sessions. Exploitation observed since Aug 20. Huntress and SecurityWeek (Sep 14) treat this as active propagation risk for MSP/enterprise remote-support fleets — not a published global compromise count. Org totals: Undisclosed.
CISA added CVE-2026-84869 to KEV on Sep 11 with a BOD 26-04 remediation due date of Sep 14 — today. Underwrite sheet: primary is ConnectWise’s Trust bulletin; secondary is Huntress on the worm chain and SecurityWeek on the KEV amplification. Patch on-prem to 26.6.5 now; hunt audit logs for Guest RunFiles/RanFiles of Windows Script Host payloads.
