Our takeConnectWise ScreenConnect versions before 26.6.5 are actively exploited in the wild, per CCCS advisory AV26-903. Update immediately if you run it yourself.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:Apply the ScreenConnect 26.6.5 update immediately; CVE-2026-84869 is under active exploitation per CCCS advisory AV26-903.
What this means for you — Lean IT orgs:If you use ConnectWise ScreenConnect, update it to version 26.6.5 right away. Most teams without an in-house security person should check with their MSP or IT provider to confirm the patch is applied.
What this means for you — MSP:Review all client instances of ConnectWise ScreenConnect and upgrade any version prior to 26.6.5; active exploitation of CVE-2026-84869 is confirmed by CCCS.
What this means for you — Researcher:CCCS AV26-903 confirms active exploitation of CVE-2026-84869 in ConnectWise ScreenConnect < 26.6.5.