Back

CRITICAL KEV

ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions

Published Sep 8, 2026 ·Due Sep 14, 2026

Description

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

Affected products

Remediation

Vendor solution

Cloud: Updated to the latest release. We recommend that partners reinstall their host clients https://docs.connectwise.com/ScreenConnect_Documentation/Get_started/Host_client/Reinstall_the_host_client and update their access agents https://docs.connectwise.com/ScreenConnect_Documentation/Get_started/Host_page/Reinstall_and_upgrade_an_access_agent .

On-prem: Upgrade to ScreenConnect client version 26.6.5 or later.

Automate-integrated ScreenConnect deployments: Automate partners are eligible to update their integrated on-premises ScreenConnect installation as long as their Automate Assurance subscription is active. Automate partners should apply the ScreenConnect 26.6.5 update through Automate Product Updates.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ConnectWise
Published Sep 8, 2026
Updated Sep 12, 2026
Reserved Sep 2, 2026
CISA Vulnrichment
Updated Sep 11, 2026
NVD
Status Analyzed
Modified Sep 12, 2026
Red Hat
Severity n/a
Public date n/a