Home About Services Support Contact Projects Blog Podcast
216.785.2700 support@microadv.com Login

Critical ScreenConnect Vulnerability Is Being Actively Exploited: What Small Businesses Should Do Now

The Tool Your IT Department Uses Can Also Be a Target

Remote-support software is essential for modern IT.

It allows an internal technician or managed service provider to troubleshoot a computer, install software, investigate problems, and provide support without physically sitting in front of the machine.

That convenience also makes remote-access software extremely valuable to attackers.

On September 8, 2026, ConnectWise released ScreenConnect version 26.6.5 to address CVE-2026-84869. According to the company's security bulletin, the vulnerability affects the ScreenConnect client and can, under certain conditions, allow files to be transferred and executed during an active remote session without proper authorization or confirmation from the host user. Versions prior to 26.6.5 are affected. ConnectWise

The vulnerability does not mean that anyone on the internet can instantly compromise every ScreenConnect installation. Exploitation requires additional access or circumstances, which is why understanding the actual mechanics matters.

But the potential impact is serious.

ConnectWise assigned the vulnerability a 9.9 CVSS score, reflecting potentially high impact to confidentiality, integrity, and availability. ConnectWise

Active Exploitation Changes the Conversation

Security vulnerabilities are disclosed every day.

Most never become widely exploited.

This one deserves additional attention because it has moved beyond being a theoretical risk.

On September 11, the Canadian Centre for Cyber Security updated its advisory to note that CISA had added CVE-2026-84869 to its Known Exploited Vulnerabilities catalog, indicating evidence of exploitation in the wild. Canadian Centre for Cyber Security

Security reporting later highlighted CISA's warning that attackers were exploiting the vulnerability, increasing the urgency for organizations that had not yet updated ScreenConnect. BleepingComputer

For businesses, that distinction matters.

Once defenders know attackers are actively targeting a vulnerability, the question should change from:

"When can we schedule this update?"

to:

"Are we exposed right now?"

Why Remote-Management Tools Are Such Attractive Targets

Remote monitoring and management software—often called RMM software—exists specifically to give technicians powerful access to computers.

Depending on the product and configuration, an RMM platform may allow authorized technicians to:

  • Remotely control desktops
  • Transfer files
  • Install software
  • Execute commands or scripts
  • Restart computers
  • Access administrative tools
  • Troubleshoot servers
  • Manage large numbers of computers simultaneously

Those capabilities are extremely useful when they're in the hands of your IT provider.

They're equally useful to an attacker.

That is why criminals increasingly attempt to either compromise legitimate remote-management platforms or install their own unauthorized remote-access tools.

Huntress recently documented several unrelated incidents involving rogue ScreenConnect installations that executed a multi-stage VBScript attack chain. Researchers observed behavior capable of establishing persistence, profiling security software, installing additional tooling, and in some scenarios spreading malicious scripts when new ScreenConnect connections were made. Huntress

Those incidents should not automatically be assumed to have resulted from CVE-2026-84869, but they illustrate the larger cybersecurity problem: remote-access tools have become valuable infrastructure for attackers.

Small Businesses Have an Additional Risk

Large organizations often have dedicated security teams monitoring remote-management software.

Many small businesses do not.

Instead, businesses may have accumulated multiple remote-support tools over the years.

An organization might have:

  • The current IT provider's remote agent
  • An old provider's remote agent
  • TeamViewer from a previous project
  • AnyDesk installed by a vendor
  • ScreenConnect installed by a software company
  • Quick Assist built into Windows
  • Another RMM tool installed for equipment support

Sometimes nobody knows all of them are there.

That creates a problem.

Every remote-management application represents another pathway into a computer. Even legitimate software can become dangerous when it is outdated, misconfigured, compromised, or simply forgotten.

What ScreenConnect Customers Should Do

Businesses using ScreenConnect should verify their environment rather than assuming someone else has handled it.

Update ScreenConnect

ConnectWise says organizations running on-premises ScreenConnect should upgrade to version 26.6.5 or later. Versions before 26.6.5 are affected. ConnectWise

ConnectWise reports that its cloud-hosted ScreenConnect environments have already been automatically upgraded, but administrators should still verify their environment and ensure associated clients and access agents are current. ConnectWise

Use the Temporary Mitigation Only If Necessary

Organizations unable to update immediately can temporarily disable the TransferFiles permission for ScreenConnect roles.

ConnectWise specifically states that this is a temporary mitigation and not a substitute for installing the security update. ConnectWise

Review ScreenConnect Users and Permissions

After updating, businesses or their IT providers should review:

  • Authorized ScreenConnect users
  • Administrator accounts
  • Technician permissions
  • Session groups
  • Old or unused accounts
  • MFA configuration
  • Audit logs

ConnectWise specifically recommends reviewing users and roles, removing unrecognized accounts, changing passwords where appropriate, and enabling multifactor authentication. ConnectWise

Don't Stop at ScreenConnect

The larger lesson applies to every remote-access product in your environment.

Businesses should maintain an inventory of approved remote-support software and remove anything that is no longer required.

A good review should answer several basic questions:

What remote-access tools are installed?

You cannot secure software you don't know exists.

Who can use them?

Access should be limited to authorized technicians and vendors.

Is MFA required?

A stolen password should not be enough to remotely control company computers.

Are technicians using individual accounts?

Shared administrator accounts make auditing significantly more difficult.

Are old vendors still able to connect?

Access should be removed when relationships end.

Are remote-support tools patched automatically?

Critical security updates should not depend on someone remembering to manually check a website every few months.

Are logs being reviewed?

Unexpected remote sessions, unusual login locations, unauthorized technicians, or abnormal file-transfer activity should be investigated.

Endpoint Detection Still Matters

Updating vulnerable software is critical, but patching alone does not guarantee that an environment is clean.

If attackers compromised a machine before the vulnerability was patched, simply updating the application does not necessarily remove whatever they installed afterward.

Businesses should use modern endpoint detection and response technology to identify suspicious processes, scripts, persistence mechanisms, or remote-management applications.

Huntress' investigation into rogue ScreenConnect activity, for example, identified malicious behavior involving Windows Script Host, PowerShell-related activity, additional remote-management software, and persistent startup mechanisms. Huntress

That kind of behavior can be difficult to identify with traditional antivirus alone.

Remote Access Should Be Treated Like a Privileged Account

Businesses often protect administrator passwords carefully but overlook remote-support platforms.

They should be treated with similar importance.

A remote-management account can sometimes provide access to dozens, hundreds, or even thousands of computers.

That makes several controls particularly important:

  • Multifactor authentication
  • Least-privilege permissions
  • Strong unique passwords
  • Individual technician accounts
  • Regular access reviews
  • Centralized logging
  • Endpoint monitoring
  • Rapid security patching

For organizations using an outside IT provider, it is reasonable to ask:

"What remote-access software do you use on our computers, and how is it secured?"

A qualified provider should be able to answer that question.

What Businesses Should Do This Week

This incident provides a good reason for organizations to perform a simple remote-access security review.

Start by identifying every RMM and remote-support application installed across company computers and servers.

Verify that those applications are still needed.

Confirm that supported versions are installed.

Require MFA for technician access.

Review old accounts and vendors.

Examine recent remote sessions for unusual activity.

Make sure endpoint protection is actively monitoring computers.

And verify that backups are available if a compromised endpoint or server ever needs to be rebuilt.

The important takeaway is not that businesses should stop using remote support.

Remote management is an important part of modern IT.

The goal is to make sure only the right people can use it—and that the software providing that access is properly secured.

How MicroAdvantage Can Help

At MicroAdvantage, we help businesses evaluate more than just whether antivirus software is installed.

A strong cybersecurity environment requires visibility into the entire technology stack.

That includes:

  • Remote monitoring and management software
  • Microsoft 365 security
  • Microsoft Defender and EDR
  • Multifactor authentication
  • Conditional Access
  • Patch management
  • Administrative accounts
  • Firewalls and networks
  • VPN and remote-access security
  • Email protection
  • Backup and disaster recovery
  • Server and workstation security

MicroAdvantage can help identify outdated or unauthorized remote-access tools, review technician access and permissions, verify patch levels, strengthen endpoint protection, and look for gaps that could give attackers an unnecessary foothold.

If you're not sure who can remotely access your company's computers—or what software gives them that ability—that is something worth reviewing before an attacker answers the question for you.


Sources

ConnectWise — ScreenConnect 26.6.5 Security Patch, published September 8, 2026. ConnectWise ScreenConnect security bulletin

Canadian Centre for Cyber Security — ConnectWise Security Advisory AV26-903, published September 9 and updated September 11, 2026. Canadian Centre for Cyber Security advisory

Huntress — Research into rogue ScreenConnect installations and worm-like activity, updated September 9, 2026. Huntress ScreenConnect threat research

BleepingComputer — Critical ScreenConnect flaw now actively exploited in attacks, published September 16, 2026. Read the active-exploitation report




« Back to the blog