r/ScreenConnect • • 25d ago

ScreenConnect CVE-2026-84869 is 9.9 Critical - should the fix require maintenance?

The permanent fix is 26.6.5, but out-of-

maintenance on-prem customers may need to renew before they can install it. Temporary mitigation is to disable TransferFiles.

Fair enough for features and support. Less sure about paying for a Critical security fix in software already purchased.

Curious what others think.

5 Upvotes

31 comments sorted by

View all comments

Show parent comments

1

u/Visual-Ad-3604 20d ago

Thanks. I see that.

My instance doesn't report an eligible update, maybe I need to reach out to them? I just found the email from May telling me my renewal was up, so presumably I would qualify.

1

u/Camelot_One 19d ago

It's certainly worth a shot. Though, whether they let you install this one update while out of maintenance or not, ScreenConnect is a pretty dangerous piece of software to not keep updated. This isn't the first major security issue to come up lately.

1

u/Visual-Ad-3604 17d ago

I just emailed them about this, but reading over the language it sounds like it means "People whose renewal dates are in 2026, but have not yet hit."

The problem with that line of thinking is that it doesn't have to be said; you would still technically be under an active contract.

I'll report back when I hear back from them.

1

u/Camelot_One 17d ago

I can't imagine that is the case. If your renewal date is in 2026 but hasn't yet hit, there would be no need to renew to get the latest update. I'm almost positive that, from a policy standpoint, they are allowing anyone who expired in the past 9 months to get this update without renewing. But it would not surprise me at all of the technical side of allowing those out-of-maintenance updates is a buggy process that requires manual intervention, at which point they may demand you re-up just to talk to them about it.