• CISA's 14 September remediation deadline has passed for federal agencies affected by the actively exploited ScreenConnect flaw
  • ConnectWise says the vulnerable component is the client, meaning host clients and access agents still need to be updated even where cloud servers are current

The fact

CISA's 14 September remediation deadline has passed for US federal civilian agencies affected by CVE-2026-84869, an actively exploited ScreenConnect vulnerability added to its Known Exploited Vulnerabilities catalogue on 11 September. The deadline applies to covered federal agencies rather than private organisations.

ConnectWise says the flaw affects the ScreenConnect client and can, under certain conditions, allow files to be transferred and executed during an active remote session without the expected authorisation or confirmation from the host. ScreenConnect servers are not the vulnerable component, and the company released version 26.6.5 to address the issue.

For cloud customers, ConnectWise says the server side has already been updated, but host clients and access agents still need to be refreshed. Operators running ScreenConnect on their own servers must also follow the vendor's upgrade instructions. Huntress has separately reported attacks involving rogue or modified ScreenConnect clients, but those incidents do not show that every legitimate installation has been compromised.

The assessment

Because the vulnerable component sits on the client side, an updated server does not show whether the fix has reached every computer using ScreenConnect. A provider can have its central service on the current release while some customer machines are still running software that needs to be refreshed.

That makes the endpoint inventory important. Support providers need to know which host clients and access agents have been updated and which remain outstanding. This can become more difficult when software is spread across several customer environments, particularly where individual organisations control when their machines can be changed.

Huntress's reporting is also a reminder that patching and incident response answer different questions. Updating the client closes the known flaw. If a machine has already shown suspicious ScreenConnect activity, the provider still needs to check what happened before the update and whether anything else was changed.

For BTW readers, the job is not finished when the central service shows the latest version. Providers need to know which customer machines have been updated, which are still outstanding and whether any require further investigation. That is the evidence customers can use to judge whether the issue has actually been contained.

What to watch

Watch whether providers can account for host-client and access-agent versions across the systems they support, including machines still awaiting an update. Where suspicious ScreenConnect activity has been found, incident-response findings will also matter because an upgrade alone cannot determine whether a system was compromised beforehand.