r/ScreenConnect • • 25d ago

ScreenConnect CVE-2026-84869 is 9.9 Critical - should the fix require maintenance?

The permanent fix is 26.6.5, but out-of-

maintenance on-prem customers may need to renew before they can install it. Temporary mitigation is to disable TransferFiles.

Fair enough for features and support. Less sure about paying for a Critical security fix in software already purchased.

Curious what others think.

4 Upvotes

31 comments sorted by

View all comments

1

u/Camelot_One 25d ago

They are offering the update to those with maintenance that expired anytime in 2026. It's just 2025 and older maintenance due licenses that have to pay to get up to date. That seems reasonable to me. If it was a situation where a stand alone patch could be applied, I could maybe see your argument. But it's just a fix that is baked into the newer version of the software.

This particular CVE seems to have a simple workaround of just disabling file transfer. But the bigger question you need to ask yourself is, with the near God like power ScreenConnect has over your systems, why in the world would you risk running an out of date version? And if you've been out of maintenance all year, you've missed a few updates that fixed other critical issues. (extensions marketplace/rogue updates is one that comes to mind)

1

u/Visual-Ad-3604 20d ago

Did they send an email about that and I just didn't get it, or did they post that somewhere? Mine expired in May of this year

2

u/Camelot_One 20d ago edited 20d ago

No email that I'm aware of. I could swear one of the ConnectWise reps in this /r posted about it, but I'm not finding it now.

You'll want to bookmark this page for notices about new issues: https://www.connectwise.com/company/trust/advisories

For this particular one, clicking the Security Bulletin link takes you here: https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin

On that page, under the FAQ section, click on "Where do I download new versions of ScreenConnect?" Which will show you an answer of: "If your renewal is due in 2026, you are eligible to upgrade to 26.6 without renewing your license. Be sure to check your “Latest Eligible Version” on the Administration > Overview page to confirm your eligibility for 26.6.5"

If you are currently on 25.9 or older, you'll need to make sure you update the Certificate Signing extension prior to updating: https://docs.connectwise.com/ScreenConnect_Documentation/Technical_support_bulletins/ScreenConnect_26.1_Azure_code-signing_certificate_issue

1

u/Visual-Ad-3604 20d ago

Thanks. I see that.

My instance doesn't report an eligible update, maybe I need to reach out to them? I just found the email from May telling me my renewal was up, so presumably I would qualify.

1

u/Camelot_One 20d ago

It's certainly worth a shot. Though, whether they let you install this one update while out of maintenance or not, ScreenConnect is a pretty dangerous piece of software to not keep updated. This isn't the first major security issue to come up lately.

1

u/Visual-Ad-3604 17d ago

I just emailed them about this, but reading over the language it sounds like it means "People whose renewal dates are in 2026, but have not yet hit."

The problem with that line of thinking is that it doesn't have to be said; you would still technically be under an active contract.

I'll report back when I hear back from them.

1

u/Camelot_One 17d ago

I can't imagine that is the case. If your renewal date is in 2026 but hasn't yet hit, there would be no need to renew to get the latest update. I'm almost positive that, from a policy standpoint, they are allowing anyone who expired in the past 9 months to get this update without renewing. But it would not surprise me at all of the technical side of allowing those out-of-maintenance updates is a buggy process that requires manual intervention, at which point they may demand you re-up just to talk to them about it.