← nejvýznamnější zprávy

SPOJENO AI KEV ✓ EPSS 0.01

Critical ScreenConnect flaw now actively exploited in attacks

Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]

6 zpráv z 5 zdrojů · první 7. 9. 12:06 · poslední 16. 9. 13:14 CZ · EN/orig

ConnectWise US IT CA FI

tg: zneužíváno tg: zranitelnost

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-84869 9.9 3.1 · ConnectWise KEV ✓ 0.01

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.

Dalších 3 CVE zmiňuje jen text zpravodajského článku (CVE-2024-1709, CVE-2025-3935, CVE-2026-3564). Nejsou to identifikátory téhle události, proto nejsou v tabulce ani v odznacích.

Jak se o tom psalo 6

  1. · BleepingComputer US nadpis události

    Critical ScreenConnect flaw now actively exploited in attacks

    Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]

  2. · CSIRT Itálie (ACN) IT

    Rilevato sfruttamento della CVE-2026-84869 relativa al prodotto ConnectWise ScreenConnect

    Rilevato lo sfruttamento attivo in rete della vulnerabilità CVE-2026-84869 con gravità "critica" - già sanata dal vendor - relativa al prodotto ConnectWise ScreenConnect

  3. · CISA KEV US

    ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability (CVE-2026-84869)

    CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog. Affected product: ConnectWise ScreenConnect. Remediation due date: 2026-09-14.

  4. · Cyber Centre Kanada CA

    ConnectWise security advisory (AV26-903)

    Serial number: AV26-903Date: September 9, 2026 As of September 8, 2026, ConnectWise is affected by a vulnerability in the following product: ScreenConnect versions prior to 26.6.5 Open-source reporting indicates that CVE-2026-84869 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. ScreenConnect 26.6.5 Security Patch ConnectWise - Security Bulletins

  5. · NCSC-FI FI

    September 3, 2026: ScreenConnect® Remote Access: Guest File Transfer Advisory

    Classification: Severe, Solution: Workaround, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: , Summary: ConnectWise has identified an issue affecting file transfer behavior in ScreenConnect® Remote Access Support and Access sessions. The issue affects both Cloud and On-Premise deployments. A CVE identifier and an official fix will be issued within the week. Until the official fix is available, partners can reduce risk today by disabling the ability for technicians to transfer files. This…

  6. · BleepingComputer US

    ConnectWise warns of new ScreenConnect flaw without patch

    ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. [...]