The Remote Access Software Nobody Bought Is the One to Worry About
A critical flaw in the remote-access software your IT provider probably uses was patched September 8 and is already being exploited. The more useful story is about the copy nobody bought.
On September 8, ConnectWise patched a serious flaw in ScreenConnect — remote-access software more than 100,000 IT providers use to reach clients' machines. Three days later it was on the government's list of flaws criminals are actively using, with a three-day federal deadline. Worth saying plainly: we moved off ScreenConnect and ConnectWise recently — for our own reasons, and before any of this was published. That doesn't make us clever. What we run now is the same category of software this article is about. We're not naming it, for the reason this article is about: the fastest way into a business is a convincing stranger naming a tool you already trust. If you've never bought ScreenConnect, don't skip this. The more useful half is about businesses that never had it — until somebody else did. The technical part — you can skip this box CVE-2026-84869, published September 8, 2026. CVSS version 3.1 base score 9.9 — Critical. ConnectWise's description: "A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances." Classified as improper privilege management and missing authorization. ScreenConnect builds before 26.6.5.9742 are the affected ones; 26.6.5 and later carry the fix. Added on September 11, 2026 to the Known Exploited Vulnerabilities catalog kept by CISA, the Cybersecurity and Infrastructure Security Agency, with a federal remediation deadline of September 14. ConnectWise's own bulletin could not be retrieved for this article; the version and score detail above is from NIST's National Vulnerability Database record, which carries ConnectWise's own text because ConnectWise assigns its own catalog numbers. What that actually means "Without host confirmation" is the part that matters. Remote-access software normally asks permission before dropping a file on your machine — that prompt is the safety rail. This flaw let a file arrive and run without it. A catalog number like CVE-2026-84869 is just a case number, so everyone means the same flaw. The list that matters is the government's much shorter register of flaws criminals are already using — this went on it three days after the fix existed. Which way the version numbers run. Anything older than 26.6.5 is exposed; 26.6.5 and newer is fixed. Bigger is safer. The part nobody bought Before any of this was public, the security firm Huntress watched attackers do something simpler: persuade people to install their own copy of ScreenConnect — through fake support calls, phishing, legitimate-looking download pages — then used that perfectly functional session to reach every other machine. It was installed by the person at the keyboard, on purpose, because somebody convincing asked. That's the version that reaches a fifteen-person office: not a defect in something you bought, but a tool working as designed, in the wrong hands. What to do, and most of it takes ten minutes Ask whoever handles your IT one question: are we on ScreenConnect 26.6.5 or later? If they run it, that's a one-sentence answer. If not, ask what they do run and when it was last updated. Then look at your own machines for remote-access software nobody authorised. On Windows: Settings, Apps, Installed apps. Sort by install date and read the recent end. You're looking for anything that lets someone else drive the computer — ScreenConnect, AnyDesk, TeamViewer and their equivalents are all legitimate products, which is exactly why attackers reach for them. If we manage your machines, call us before uninstalling anything. You'll find remote-access and monitoring software there; it's ours. Pulling it is how you end up with a problem nobody sees. And tell your people the rule that prevents all of it: nobody from Microsoft, your bank, or your IT company will ever ring out of the blue and ask you to install something. Not once. If that happens, hang up and ring the number you already have.