Home / Insights / Article

// Darksteel Insights · 2026-09-12

SMBs Urged to Patch ConnectWise ScreenConnect Vulnerability

A vulnerability in ConnectWise ScreenConnect is being actively exploited, and SMBs must take immediate action to patch and secure their systems.

The short version
  • A vulnerability in ConnectWise ScreenConnect is being exploited in the wild.
  • SMBs using ScreenConnect must apply patches by September 14.
  • Confirm your systems are patched and secure access to ScreenConnect.
  • Contact your IT provider for help if unsure how to proceed.

What is this vulnerability and why is it a concern?

CVE-2026-84869 is a flaw in ConnectWise ScreenConnect, a remote support tool used by many SMBs to manage customer systems. The issue is related to improper privilege management and missing authorization checks, which can allow attackers to access systems they shouldn’t be able to.

Because this flaw is now being actively exploited, it’s urgent for businesses using ScreenConnect to take action. Attackers could gain access to systems and perform actions without needing to bypass other security tools.

The flaw is concerning because it doesn’t require user interaction or special privileges. Once an attacker gains access, they can move through your network in ways that are hard to detect.

How does this affect SMBs?

If your business uses ConnectWise ScreenConnect, you are at risk. The flaw allows attackers to bypass authentication and access sensitive systems or data. This could lead to data breaches or system disruptions.

Many SMBs rely on ScreenConnect for customer service and IT support. If not patched quickly, an exploit could disrupt your operations and damage your reputation.

The risk isn’t limited to your internal network. If you use ScreenConnect to support external customers, the vulnerability could also affect those systems, exposing your business to legal and compliance risks.

What should you do this week?

First, confirm whether your business is using ConnectWise ScreenConnect. If you are, check the version you're running. ConnectWise has released a patch to address this vulnerability, and it's important to apply it as soon as possible.

If you're unsure how to apply the patch or if you're using a managed service provider, contact your IT team or vendor immediately. They should be able to verify the patch status and apply it if needed. The federal remediation deadline is September 14, so there's no room for delay.

In addition to patching, review your access controls and ensure that only authorized personnel have access to ScreenConnect. This includes limiting who can log in and what actions they can perform.

How can you tell if you've already been hit?

Detecting a compromise can be difficult, but there are signs to watch for. Look for unusual login activity, especially from unfamiliar IP addresses, or unexpected system behavior such as files being altered or deleted.

Check your logs for unauthorized access attempts or failed login attempts that may indicate an attacker is probing your systems. If you notice anything suspicious, investigate immediately.

If you suspect a breach, isolate the affected systems and contact a cybersecurity professional for a full assessment.

Not sure whether your environment is exposed? That is exactly what our Vulnerability Management service is built to surface. Talk to us.

Frequently asked questions

What is ConnectWise ScreenConnect?
ConnectWise ScreenConnect is a remote support tool used by IT service providers and businesses to manage and support customer systems remotely. It allows technicians to access and control customer devices as if they were on-site.
How can I check if I'm using ScreenConnect?
If your business provides remote IT support or uses remote access tools, you may be using ScreenConnect. Check with your IT team or service provider to confirm the software and version in use.
What should I do if I can't patch immediately?
If you're unable to apply the patch right away, disable or restrict access to ScreenConnect until the patch can be applied. This can help reduce the risk of exploitation while you work on a permanent fix.
Can this vulnerability lead to ransomware?
There is no confirmed evidence that this vulnerability is being used to deploy ransomware at this time.
What if I'm not using ScreenConnect?
If your business isn't using ConnectWise ScreenConnect, you're not directly affected by this vulnerability. However, it's still a good idea to ensure all your software is up to date and that you're following best practices for cybersecurity.

Source (public domain): CISA