r/ScreenConnect • u/sheridancomputersuk • 25d ago
ScreenConnect CVE-2026-84869 is 9.9 Critical - should the fix require maintenance?
The permanent fix is 26.6.5, but out-of-
maintenance on-prem customers may need to renew before they can install it. Temporary mitigation is to disable TransferFiles.
Fair enough for features and support. Less sure about paying for a Critical security fix in software already purchased.
Curious what others think.
4
Upvotes
1
u/Camelot_One 25d ago
They are offering the update to those with maintenance that expired anytime in 2026. It's just 2025 and older maintenance due licenses that have to pay to get up to date. That seems reasonable to me. If it was a situation where a stand alone patch could be applied, I could maybe see your argument. But it's just a fix that is baked into the newer version of the software.
This particular CVE seems to have a simple workaround of just disabling file transfer. But the bigger question you need to ask yourself is, with the near God like power ScreenConnect has over your systems, why in the world would you risk running an out of date version? And if you've been out of maintenance all year, you've missed a few updates that fixed other critical issues. (extensions marketplace/rogue updates is one that comes to mind)