CiberLATAMbywhalemate

CISA Confirms Active Exploitation of ScreenConnect

CISA confirmed active exploitation of CVE-2026-84869 in ScreenConnect. ConnectWise told customers to update to 26.6.5

Whalemate Labs · AI-assisted researchPublished:2 min read

CISA confirmed active exploitation of CVE-2026-84869 in ConnectWise ScreenConnect. ConnectWise told on-premises customers to move to version 26.6.5 or later and review clients and agents after patching.

CISA has confirmed active exploitation of CVE-2026-84869 in ConnectWise ScreenConnect, while ConnectWise told on-premises customers to update to version 26.6.5 or later and review clients and agents after patching. The case was also added to CISA KEV, with a federal remediation deadline set for September 14, 2026, and guidance to carry out forensic triage.

What do we know about ScreenConnect exploitation?

CISA said CVE-2026-84869 is being actively exploited, and the KEV record added the need to prioritize remediation before September 14, 2026. Available information lists use in ransomware campaigns as unknown, so there is no confirmed attribution to that type of operation.

Technical guidance shared by the Aviatrix Threat Research Center says ConnectWise recommended that on-premises environments move to version 26.6.5 or later. After patching, the company asked administrators to review clients and agents, a step meant to verify the status of deployed components in each instance.

What other relevant findings appeared in the same period?

The week’s material also includes a separate campaign, KREMLIN, documented by Elastic Security Labs and published in Telefónica Tech’s bulletin. The banking malware has been active since May 2025 and impersonates a dozen Brazilian banks, although it is not tied to a specific CVE.

Independent sources cited by Elastic Security Labs reported 1,515 identified systems affected by KREMLIN, with about 98% geolocated in Brazil. The malware steals credentials, cookies, and sessions through malicious Chrome and Edge extensions, allowing it to capture login data from browsers used by victims.

The technical coverage also says the command-and-control infrastructure can be updated through Ethereum smart contracts, a method that complicates conventional takedown of attack servers. F4N6 said the operation has no CVE, no CVSS score, and no CISA KEV entry, and that it relies on social engineering, user execution, DLL side-loading, and bypassing Chromium integrity controls.

Sources

View all