ConnectWise security advisory (AV26-903) – Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial number: AV26-903 Date: September 9, 2026 Updated: September 11, 2026 As of September 8, 2026, ConnectWise is affected by a vulnerability in the following product: ScreenConnect versions prior to 26.6.5 Open-source reporting indicates that CVE-2026-84869 is being exploited in the wild. Update 1 On September 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-84869 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. ScreenConnect 26.6.5 Security Patch ConnectWise - Security Bulletins CISA KEV: CVE-2026-84869
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/connectwise-security-advisory-av26-903
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-84869Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 51% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-84869 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploitedCISA Adds Three Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerabilit…cisa-kev
- criticalexploitedCVE-2026-84869: A condition in the ScreenConnect client may allow files to be transferred and executed through…nvd
More from Canadian Centre for Cyber Security
- criticalGitLab security advisory (AV26-917)2026-09-11
- unknownJFrog security advisory (AV26-867) – Update 22026-09-11
- unknownn8n security advisory (AV26-916)2026-09-11
- criticalProgress security advisory (AV26-915)2026-09-11
- unknown[Control Systems] National Instruments security advisory (AV26-914)2026-09-11