ProBackend
active vulnerability exploitation
4 hours ago6 min read

AI Cybersecurity Threats in 2026: CISA Confirms a Critical ScreenConnect Flaw Is Being Exploited Right Now

CISA says attackers are actively exploiting a critical ConnectWise ScreenConnect flaw, CVE-2026-84869. Here's what the bug does, why it keeps happening, and the defenses that actually cut risk for MSPs and security teams.

A Remote Support Tool Just Became an Open Door

A tool built to help IT teams fix problems turned into a tool attackers used to create them. The U.S. Cybersecurity and Infrastructure Security Agency confirmed that attackers are exploiting a critical-severity flaw in ConnectWise ScreenConnect in the wild, and if your shop leans on ScreenConnect for remote support, this one lands squarely on your desk.

The urgency is real. CISA added the bug to its catalog of actively exploited vulnerabilities on a Friday and ordered federal agencies to lock down their systems within three days. That window is the signal. CISA does not hand out three-day clocks for theoretical risk — it hands them out when exploitation is happening and the damage is measurable.

What CVE-2026-84869 Actually Does

The vulnerability is tracked as CVE-2026-84869 and ships fixed in ScreenConnect 26.6.5 and later. At its core it combines improper privilege management with a missing authorization check. In plain terms, an attacker who already holds basic privileges can transfer files and execute them through an active remote session — without authorization and without the host confirming anything.

That last part is the knife twist. Low complexity. No user interaction. No helpful prompt asking "do you want to allow this file?" The session is already trusted, and the flaw lets the attacker ride that trust straight through to file execution. For anyone who has spent years telling users to "just don't click that," this is the kind of bug that laughs at user awareness. You cannot train your way out of a missing permission check.

Before a patch existed, ConnectWise published temporary mitigation steps on September 7, and the heart of them was blunt: disable the TransferFiles permissions to block the attack path. It is a reasonable stopgap, and it is also an admission of how dangerous the exposure was — you pull the file-transfer feature entirely because you cannot yet trust the boundary around it.

The Three-Day Clock, and Why It Matters

I want to be precise here, because hype distorts the facts and calm accuracy protects you better than fear. CISA's directive to federal agencies was to secure their systems within three days of the KEV listing. That is the verifiable timeline. Anyone telling you a different specific deadline date is going beyond what the source actually states.

For private-sector MSPs and enterprises, you are not legally bound by that federal clock. But you should treat it as your clock anyway. A three-day federal mandate is CISA's way of saying: the window between disclosure and organized exploitation has essentially collapsed. Patch on the timeline you wish you had started with, not the one an incident forces on you.

ScreenConnect Keeps Landing in the Crosshairs

Here is what should bother defenders more than any single CVE: this is not a one-off. Since 2024, CISA has flagged four separate ScreenConnect security issues as actively exploited. Two of them were also abused in ransomware attacks. When one product line keeps producing actively-exploited flaws, you stop asking "did we patch the last one?" and start asking "why is this product a recurring target, and do we need the blast radius it brings?"

The attacker roster reads like a greatest-hits of threat types. North Korean-backed Kimsuky and several ransomware gangs exploited CVE-2024-1709 back in 2024. Then, last year, ConnectWise disclosed that suspected state-sponsored hackers breached its own systems through code injection — a ViewState flaw, CVE-2025-3935 — reaching the cloud-based instances of a limited number of customers and forcing ConnectWise to rotate its digital code-signing certificates. Earlier in 2026, in March, ConnectWise patched a cryptographic signature verification vulnerability, CVE-2026-3564, that could have let attackers hijack unpatched ScreenConnect servers.

Financially motivated criminals and state-backed operators, same product, same attack surface, year after year. Both camps want the same thing: that low-friction path into environments they otherwise could not reach.

The Exposure Problem Is Still Countable

Theory is one thing. Numbers are another. Threat watchdog Shadowserver now tracks over 1,000 ScreenConnect instances still unpatched and exposed online, and the geography tells its own story. Most sit in North America (758) and Europe (180). These are not obscure servers in forgotten corners of the internet. They cluster in the regions where compliance expectations and incident-response budgets are supposedly the highest.

The scale of the dependency explains the stakes. ConnectWise provides services to more than 100,000 IT providers worldwide, and a huge share of managed service providers and internal IT teams use ScreenConnect for troubleshooting, patching, and system maintenance. ScreenConnect, in other words, sits at the center of the remote-access supply chain. Compromise one relay and you are not standing in one customer's front door — you are potentially standing in dozens of them. That is the MSP-specific nightmare this product has collected before, and it is exactly why a three-day CISA clock is not bureaucratic theater.

AI Cybersecurity Threats in 2026: A Wider Attack Surface, Not a Separate One

It is tempting to file this under "old-school vulnerability, nothing to do with AI." I think that instinct is wrong, and understanding why is the useful mental model for defending anything in 2026. The AI cybersecurity threats conversation is not really about whether a specific bug was written by a model. It is about velocity and surface area. Flaw discovery, weaponization, and mass scanning are being automated and accelerated, so the gap between "a critical remote-access CVE exists" and "it is being exploited at scale" shrinks toward zero. The three-day federal deadline is a symptom of that compression.

Worth keeping in view: remote-access and agent-style platforms are becoming a favored target precisely because they hand attackers pre-trusted, hard-to-supervise positions inside networks. The same reasoning that makes agentic AI workflows dangerous — powerful privileges, thin oversight, sessions that look legitimate — is what makes a ScreenConnect relay dangerous. If you are building defenses for autonomous or agent-driven systems, our piece on governing agentic AI workflows in the enterprise covers the trust-and-oversight failure that this ScreenConnect incident is the offline twin of. For a near-identical CISA-on-the-clock pattern involving an AI tool, see our writeup on the Langflow directive.

What to Actually Do

No philosophy, just the list. Patch every ScreenConnect deployment to 26.6.5 or later. If you cannot patch today, disable the TransferFiles permissions now, exactly as the vendor advised, because that is the verified path that blocks this attack. Then widen the lens: inventory every internet-exposed ScreenConnect instance you own or operate, and reconcile it against the Shadowserver count as a sanity check that your inventory is not lying to you. If you are an MSP, treat this as a customer-notification event, not just an internal ticket — your relay is their front door.

And step back further. Four actively-exploited ScreenConnect flaws since 2024 is not bad luck; it is a pattern. The complete defense here is not any single patch. It is deciding, deliberately, how much trust you are willing to hand any remote-access tool, and supervising that trust like the high-value position it actually is.

a remote support tool just became an open

More blogs