← back
CVE-2026-84869criticalobserved exploitationCWE-269CWE-862

ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions

50Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 9.9epss 0.4%
from disclosure to weapon
Published on NVDSep 8
VulnCheckSep 8
exploitation probability
0.4%top 68% of all CVEs
observed exploitation
yesVulnCheck
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H