# CISA Flags ScreenConnect Vulnerability

CISA added ConnectWise ScreenConnect vulnerability CVE-2026-84869, rated CVSS 9.9, to its Known Exploited Vulnerabilities catalog on September 11, 2026, and set September 14 as the remediation deadline for federal civilian agencies. That deadline has passed. Contractors and managed service providers supporting government environments should verify that ScreenConnect servers, clients, and managed endpoints run version 26.6.5 or later, review session activity, and document remediation. The signal identifies no solicitation, award, or contract opportunity.

- Federal contractors and MSPs supporting affected environments can use the version threshold and remediation recordkeeping to assess their operational exposure and support agency remediation efforts.
- Procurement and security teams should account for the vulnerability when reviewing service-provider security practices and ScreenConnect deployments; the stated federal-agency deadline is already past.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** October 01, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)

### Vendors
- ConnectWise (ScreenConnect product publisher)

### Sources
- [ScreenConnect CVE-2026-84869: CVSS 9.9 Flaw [2026]](https://shattered.io/screenconnect-cve-2026-84869-cvss-9-9-2026) - shattered.io