screenconnect-remote-support

The ScreenConnect remote support tool has a vulnerability that has already been exploited in attacks, some of which have spread like worms: during a session, an attacker can send and execute a file on a computer without confirmation (CVE-2026-84869).

ScreenConnect (formerly ConnectWise Control) is a tool that IT companies use to remotely connect to their clients' computers to troubleshoot issues. Many small businesses that work with an external IT provider have this program installed on their PCs, even if they never open it themselves. The CVE-2026-84869 vulnerability has been confirmed as being exploited in real-world attacks and has been included by the U.S. agency CISA on its list of actively exploited vulnerabilities.

The issue relates to permissions and the lack of confirmation: during a connection session, an attacker can transfer a file to the host computer and execute it without the user’s consent. Some attacks have spread from one computer to another, like a worm. A fix is available in ScreenConnect version 26.6.5 and later; until the update is installed, the developer recommends disabling file transfer permissions.

For a small business, it is precisely the trusted channel—the program through which “someone comes to help you”—that becomes the weak point. It’s not a tool you can fix on your own: updates are handled by the IT provider that uses it.

What you need to do:

  • Ask the company that manages your computers if it uses ScreenConnect and if it has updated to version 26.6.5 or later.
  • Until the update is installed, ask them to disable file transfer permissions.
  • If you have the ScreenConnect client installed on your PCs and you no longer work with the company that installed it, ask them to uninstall it.

Remote support tools have broad access to a company's computers, which is why they are a target. A message to the IT provider closes the door before it can be exploited.

Sources:

This article was generated with AI assistance.

Request a quote

← All news