CTIPilot

ConnectWise ScreenConnect client file-transfer authorization flaw, worm-like exploitation from 20 August 2026, patched 26.6.5

cve · CVE-2026-84869

Coverage timeline
1
first 2026-09-12 → last 2026-09-12
Peak priority
high
1 high
Sources cited
4
4 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
9
pinned v19.2 · see below

ATT&CK techniques

9 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Persistence TA0003

T1543.003Create or Modify System Process: Windows Service×1

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-09-12/cve-2026-84869-connectwise-screenconnect-worm-file-transfer · ATT&CK page ↗

Privilege Escalation TA0004

T1543.003Create or Modify System Process: Windows Service×1

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-09-12/cve-2026-84869-connectwise-screenconnect-worm-file-transfer · ATT&CK page ↗

T1548.002Abuse Elevation Control Mechanism: Bypass User Account Control×1

Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action.

Evidence: 2026-09-12/cve-2026-84869-connectwise-screenconnect-worm-file-transfer · ATT&CK page ↗

Stealth TA0005

T1211Exploitation for Stealth×1

Adversaries may exploit vulnerabilities to evade detection by hiding activity, suppressing logging, or operating within trusted or unmonitored components.

Evidence: 2026-09-12/cve-2026-84869-connectwise-screenconnect-worm-file-transfer · ATT&CK page ↗

Defense Impairment TA0112

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-09-12/cve-2026-84869-connectwise-screenconnect-worm-file-transfer · ATT&CK page ↗

Lateral Movement TA0008

T1570Lateral Tool Transfer×1

Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.

Evidence: 2026-09-12/cve-2026-84869-connectwise-screenconnect-worm-file-transfer · ATT&CK page ↗

Command and Control TA0011

T1090Proxy×1

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Evidence: 2026-09-12/cve-2026-84869-connectwise-screenconnect-worm-file-transfer · ATT&CK page ↗

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-09-12/cve-2026-84869-connectwise-screenconnect-worm-file-transfer · ATT&CK page ↗

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-09-12/cve-2026-84869-connectwise-screenconnect-worm-file-transfer · ATT&CK page ↗

Impact TA0040

T1496Resource Hijacking×1

Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

Evidence: 2026-09-12/cve-2026-84869-connectwise-screenconnect-worm-file-transfer · ATT&CK page ↗

Story timeline

  1. 2026-09-12CVE-2026-84869, ConnectWise ScreenConnect: a missing file-transfer authorization check lets an active remote session push and auto-run files on the Host, and Huntress traced worm-like exploitation back to 20 August, weeks before any patch existed (CVSS 9.9)
    trending-vulnerabilitiesConnectWise patches a ScreenConnect flaw Huntress had already watched turn every infected connection into the next one's launch point

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • cisa.gov1 (25%)
  • github.com1 (25%)
  • huntress.com1 (25%)
  • securityweek.com1 (25%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about ConnectWise ScreenConnect client file-transfer authorization flaw, worm-like exploitation from 20 August 2026, patched 26.6.5 (1)

2026-09-12 · view entry permalink →

HIGHCVE-2026-84869exploitedNATOA1

CVE-2026-84869, ConnectWise ScreenConnect: a missing file-transfer authorization check lets an active remote session push and auto-run files on the Host, and Huntress traced worm-like exploitation back to 20 August, weeks before any patch existed (CVSS 9.9)

ConnectWise's own disclosure describes a client-side condition in ScreenConnect Support and Access sessions where file-transfer actions could be processed through an active remote session "without proper authorization or Host confirmation," letting files be transferred to and executed on the Host system, including through elevated execution paths (ConnectWise, 2026-09-08). ScreenConnect servers are not affected, only client versions before 26.6.5, the release that fixes CVE-2026-84869 (CWE-862 Missing Authorization, CWE-269 Improper Privilege Management, CVSS 9.9).

Huntress had been tracking the exploitation for two and a half weeks before any advisory existed. Starting 20 August 2026, its SOC found rogue ScreenConnect clients deployed via social engineering (a fake tech-support Quick Assist session in one case, a phishing-driven MSI in another) that immediately spawned four chained VBScript stagers via wscript.exe. The stagers profile the host (existing ScreenConnect install, installed security-product names, available RAM to rule out a sandbox), then pull an AES-encrypted payload bundle keyed to that profile from Dropbox. Depending on the profile, the final PowerShell stage installs a ScreenConnect backdoor client concealed as a hidden Windows service, its registry Uninstall entry removed and a restrictive service security descriptor applied, builds a UAC-bypass helper via a hijacked ms-settings: protocol handler routed through ComputerDefaults.exe, sets AmsiUtils.amsiInitFailed = true to blind AMSI, adds all of C:\Users as a Defender exclusion, and disables Defender reporting, notifications and Hypervisor-Protected Code Integrity, the last of these via a vulnerable WinRing0 kernel driver dropped alongside the payload (Huntress, 2026-09-03). The broadest observed variant then drops a wstunnel tunneling tool disguised as Themes.exe and an XMRig cryptominer disguised as SearchIndex.exe.

The installed backdoor client is what turns the bug into a worm: it continuously inspects ScreenConnect's own connection-status collection for newly established Host sessions and, on each new connection, packages the same four VBScript stagers into a ScreenConnect file-transfer message flagged to auto-run, the exact abuse path CVE-2026-84869 patches. A technician's ScreenConnect client that has been infected this way silently re-infects every subsequent host it connects to, independent of the original social-engineering vector (Huntress, 2026-09-03). No named threat-actor cluster is attributed by any source; CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-09-11 with a three-day remediation deadline (CISA KEV, catalogue version 2026.09.11).

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

ConnectWise (vendor disclosure) 2026-09-08

This creates a worm-like behavior: propagating infections over new ScreenConnect connections. Connecting to an infected ScreenConnect client can cause the server-side Host system to receive and execute the same four-stage VBScript chain.

In late August, our Security Operations Center (SOC) sent out three critical incident reports for what looked like malicious ScreenConnect installation and unexpected process execution.

Huntress 2026-09-03
vulnerability12 Sep 04:09Zmulti-sourceOpen finding ↗