ScreenConnect Flaw: What Healthcare Organizations Should Verify
Published September 14, 2026
Featured image
- Concept: A healthcare administrator and an authorized IT technician reviewing remote-support access on a clinic workstation. Display a generic device-management screen without real company names, passwords, patient information, or recognizable software interfaces. Keep the mood calm, professional, and verification-focused.
- Filename:
screenconnect-vulnerability-healthcare-remote-support.jpg
- Alt text: Healthcare administrator verifies remote-support software and vendor access with an IT technician inside a clinic
Remote-support software allows an authorized technician to view or control a computer without being physically present.
That capability is valuable to medical practices, dental offices, hospice and home-health providers, outpatient clinics, and senior-care organizations. It allows technology problems to be addressed quickly across offices, clinical areas, and remote work locations.
It is also a privileged access path that must be managed carefully.
ConnectWise released a security update for a critical ScreenConnect client vulnerability on September 8, 2026. The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities Catalog on September 11 after finding evidence of active exploitation.
The vulnerability is identified as CVE-2026-84869.
Quick Answer: What should healthcare organizations do about the ScreenConnect vulnerability?
Ask the organization’s IT provider whether ScreenConnect is installed or used anywhere in the environment.
If it is, obtain written confirmation that affected clients and access agents have been updated to ScreenConnect 26.6.5 or later, that exposed permissions and active sessions were reviewed, and that relevant remote-access activity was checked for unauthorized file transfers or execution.
Do not remove remote-support software from clinical systems without coordinating with the responsible technology provider. An unplanned removal could interfere with support, monitoring, or patient-care operations.
Organizations that do not use ScreenConnect should still use the event to review every remote-support tool with access to their computers.
What happened?
On September 8, ConnectWise published a security bulletin addressing a condition in the ScreenConnect client.
According to the company, the vulnerability could allow files to be transferred and executed through an active remote session without the expected authorization or host confirmation in certain circumstances.
ConnectWise released ScreenConnect client version 26.6.5 to address the issue.
On September 11, CISA added CVE-2026-84869 to its Known Exploited Vulnerabilities Catalog. CISA adds vulnerabilities to this catalog when there is reliable evidence that attackers have exploited them.
That changes the issue from a theoretical software weakness to a confirmed, active threat.
What systems are affected?
The vulnerability concerns the ScreenConnect client used during support and access sessions. ConnectWise’s bulletin states that ScreenConnect servers are not affected by this specific vulnerability.
The required response depends on how ScreenConnect is deployed.
ConnectWise-hosted cloud environments
ConnectWise reports that its cloud service was updated. The company also recommends reinstalling host clients and updating access agents so endpoints receive the corrected client.
A cloud console being updated does not necessarily prove that every installed endpoint component has completed its update.
Self-hosted ScreenConnect environments
Organizations or providers operating an on-premises ScreenConnect installation should upgrade to version 26.6.5 or later and verify that connected clients and agents are current.
ScreenConnect integrated with ConnectWise Automate
ConnectWise Automate partners were instructed to apply the ScreenConnect 26.6.5 update through Automate Product Updates when eligible.
Healthcare customers may not know which deployment model their provider uses. That is precisely why written verification is appropriate.
Why this vulnerability matters
Remote-support tools are designed to perform sensitive actions.
Depending on their configuration and the permissions assigned, they may allow technicians to:
- View a user’s screen
- Control the keyboard and mouse
- Transfer files
- Run commands
- Install or remove software
- Work with elevated privileges
- Access systems outside normal office hours
- Connect without a user physically present
These functions make remote support efficient. They also mean that weak authorization, excessive permissions, stolen credentials, or an unpatched client may create significant risk.
The concern is not that all ScreenConnect sessions were compromised. Public guidance does not establish that every organization using the product was affected.
The correct question is whether a particular organization had an exposed version, whether the affected function was available, and whether activity during the relevant period shows anything requiring further investigation.
What healthcare leaders should ask their IT provider
Send the following questions to the person or company responsible for remote support.
1. Do we use ScreenConnect?
Ask whether it is used:
- Directly by the organization
- By its managed service provider
- Through another ConnectWise product
- By an EHR or application vendor
- By a billing or revenue-cycle vendor
- By a copier, imaging, laboratory, or medical-device vendor
- For unattended after-hours access
- On employee-owned or mobile devices
A product may appear under names such as ScreenConnect, ConnectWise Control, or a provider’s white-labeled support application.
2. Which devices have the client or access agent installed?
Request an inventory identifying:
- Device name
- Location
- Responsible department
- Installed version
- Last successful connection
- Whether unattended access is enabled
- Current update status
- Assigned access group
- Responsible vendor or administrator
Include clinical workstations, servers, laptops, home-health devices, reception computers, and administrative systems.
3. Are all affected components running version 26.6.5 or later?
Request the answer in writing.
The response should explain:
- Current server or service version
- Current client version
- Current access-agent version
- Date the update was applied
- Number of devices successfully updated
- Number of devices offline or pending
- How exceptions will be resolved
“ConnectWise handles updates” is not sufficient if local clients or agents still need to reconnect, reinstall, or complete an upgrade.
4. Were permissions reviewed?
Before the corrected version was available, ConnectWise reportedly advised administrators to restrict the TransferFiles permission for users with open sessions.
Ask whether the provider reviewed:
- File-transfer permission
- Command-execution capabilities
- Unattended-access permissions
- Administrator roles
- Technician groups
- Temporary accounts
- Former employees
- Vendor accounts
- Open or unusually long sessions
Permissions should be restored only when they are necessary and appropriately controlled.
5. Was relevant activity reviewed?
Ask whether the provider examined available records for:
- Unexpected remote sessions
- Unrecognized technician accounts
- Unusual connection times
- File transfers
- File execution
- Permission changes
- New accounts
- Modified access groups
- Connections to high-value systems
- Sessions originating from unexpected locations
The availability and detail of these records will depend on the deployment, licensing, retention settings, and logging configuration.
A lack of obvious alerts does not prove that the environment was unaffected. The provider should explain what records were available, what period was reviewed, and what the review found.
6. Were credentials or sessions reset where appropriate?
The provider should determine whether any accounts, tokens, active sessions, API connections, or authentication methods require revocation or replacement.
This decision should be based on actual exposure and evidence. Broad credential resets performed without planning can interrupt clinical operations and may not address an already active session.
7. What is the written conclusion?
Request a short statement covering:
- Whether ScreenConnect is present
- Whether vulnerable components were found
- Whether all components were updated
- Whether suspicious activity was identified
- Which devices remain pending
- Which temporary restrictions were applied
- Whether further investigation is recommended
- Who owns each remaining action
- When the next update will be provided
Avoid settling for a verbal “you should be fine.” It is a splendidly reassuring phrase and a rather poor audit record.
What should employees do?
Employees should not attempt to update, disable, or remove remote-support agents themselves unless specifically instructed.
They should report:
- Unexpected remote-control prompts
- A cursor moving without explanation
- Unapproved file-transfer notices
- New support applications
- Unusual pop-ups
- Requests to leave a computer unlocked
- Technicians they cannot verify
- Remote sessions outside expected times
- Security warnings involving support software
Employees should end or refuse an unexpected support session when safe to do so and contact the approved support channel independently.
A legitimate technician should be willing to let the employee verify the request.
Do not confuse this flaw with fake remote-support software
This event involves a vulnerability in a legitimate ScreenConnect client.
Attackers also abuse legitimate remote-support products in other ways. They may:
- Trick an employee into installing an unauthorized agent
- Use a trial account
- Steal a technician’s credentials
- Impersonate the help desk
- Send a fake software-update notice
- Rename a remote-access tool
- Install more than one persistence tool
Updating ScreenConnect addresses this specific vulnerability. It does not replace controls for technician identity, software installation, MFA, access approval, logging, or vendor oversight.
Why this matters to healthcare organizations
Independent medical and dental practices
A remote-support agent may exist on every workstation while technology is managed by one outside provider. Practice leadership may never see the management console and must rely on its provider for accurate verification.
Hospice and home-health providers
Remote employees and mobile devices can be difficult to update consistently. Devices that have been offline may remain pending until they reconnect.
Assisted-living and senior-living organizations
Unattended remote access may be used to support nursing stations, medication-related systems, administrative computers, and after-hours operations. Access should be limited without making legitimate support unavailable during a care disruption.
Outpatient clinics
Remote-support software may reach EHR-connected computers, Microsoft 365, imaging workstations, billing systems, and shared clinical devices. A current device inventory is essential for verifying coverage.
Healthcare organizations using multiple vendors
Separate vendors may install separate support agents. An organization may have tools from its MSP, EHR vendor, copier provider, imaging company, and specialty application vendors on the same device.
Without an inventory, leadership may not know how many outside access paths exist.
What if the organization does not use ScreenConnect?
Use this incident as a reason to review other remote-support tools.
Ask:
- Which products are installed?
- Which company owns each installation?
- Which employees or vendors can connect?
- Is unattended access enabled?
- Is MFA required for technicians?
- Are sessions logged?
- Are clients and agents updated automatically?
- How are former technicians removed?
- Can file transfer or command execution be restricted?
- Who reviews remote-access activity?
The goal is not to ban remote support. The goal is to make every access path known, owned, current, restricted, and reviewable.
A practical response checklist
Protect
- Identify every remote-support product.
- Update ScreenConnect clients and agents to 26.6.5 or later.
- Require MFA for technician accounts.
- Remove inactive accounts.
- Limit unattended access.
- Restrict file transfer and command execution to authorized roles.
- Separate ordinary and administrative identities.
Operate
- Maintain a device and remote-access inventory.
- Record the owner and purpose of every agent.
- Establish a verification procedure for support sessions.
- Review vendor access periodically.
- Define expected support hours.
- Retain appropriate session and administrative logs.
- Document the update and exception process.
Recover
- Revoke suspicious sessions and credentials.
- Preserve relevant logs and vendor communications.
- Isolate affected devices when technically and clinically appropriate.
- Coordinate specialized investigation if evidence warrants it.
- Validate systems before returning them to ordinary use.
- Document restoration and unresolved risks.
Grow
- Add remote-support requirements to vendor contracts.
- Review access during employee and vendor offboarding.
- Reduce duplicate or abandoned support agents.
- Test how support will work during an outage.
- Include privileged vendor access in technology assessments.
- Require written security notices and remediation confirmation.
The bottom line
CISA’s confirmation of active exploitation makes CVE-2026-84869 an issue that ScreenConnect users should address promptly.
Healthcare organizations do not need to perform the technical work themselves. They should obtain clear answers from the person or company responsible for remote support.
Start with four questions:
- Is ScreenConnect installed anywhere?
- Are all clients and agents running version 26.6.5 or later?
- Were permissions, sessions, and relevant logs reviewed?
- Can the provider document the result?
Remote support should make healthcare technology easier to operate. It should not become an undocumented doorway whose owner, version, and permissions are unknown.
Frequently asked questions
What is ScreenConnect?
ScreenConnect is a remote-support and remote-access product from ConnectWise. Authorized technicians can use it to view or control computers, transfer files, run support tools, and maintain systems from another location.
What is CVE-2026-84869?
It is a vulnerability in the ScreenConnect client that may allow unauthorized file transfer and execution through an active remote session under certain conditions.
Is the ScreenConnect vulnerability being actively exploited?
Yes. CISA added CVE-2026-84869 to its Known Exploited Vulnerabilities Catalog on September 11, 2026, based on evidence of active exploitation.
Which ScreenConnect version contains the fix?
ConnectWise released the fix in ScreenConnect client version 26.6.5. Organizations should use version 26.6.5 or a later vendor-supported release.
Are ConnectWise-hosted cloud customers protected automatically?
ConnectWise reports that its cloud service was updated. However, customers and providers should still verify that installed host clients and access agents have been reinstalled or updated as recommended.
Should employees uninstall ScreenConnect?
Not without authorization. Removing a legitimate support agent may interrupt monitoring or technical assistance. The responsible IT provider should verify the version and determine the appropriate action.
What if a healthcare organization uses another remote-support product?
The specific ScreenConnect patch does not apply, but the broader lesson does. Inventory the tool, confirm ownership, review privileged access, require strong authentication, verify updates, and retain appropriate activity records.
Strengthen your healthcare technology readiness
Vault Technologies helps healthcare organizations improve endpoint administration, remote-support governance, access controls, vendor documentation, patch coordination, and incident-management readiness.
Our nurse-led perspective keeps security decisions connected to patient care, clinical workflows, shift coverage, and safe technology operations.
Request a complimentary Technology Health Assessment to establish a practical baseline across endpoint management, vendor access, Microsoft environments, documentation, backup planning, and care-continuity readiness.
The assessment is a planning tool. It is not a legal opinion, compliance certification, penetration test, forensic investigation, or guarantee against cyber incidents.
Authoritative sources
- ConnectWise — September 8, 2026 ScreenConnect security bulletin, published September 8, 2026.
- CVE Program — CVE-2026-84869 record, published September 8, 2026.
- CISA — Known Exploited Vulnerabilities Catalog, ScreenConnect entry added September 11, 2026.
- ConnectWise — public disclosure repository for CVE-2026-84869, published September 8, 2026.
- NHS England Digital — “ConnectWise Releases Security Update for ScreenConnect”, published September 9, 2026.
- Computerworld — “ConnectWise patches critical ScreenConnect authentication failure after five days”, published September 11, 2026.
Recent Posts








