The National Vulnerability Database has published CVE-2026-89009, a critical vulnerability (CVSS 9.1) affecting WAVLINK WN535M1 and WN535M3 routers running firmware versions prior to M35M1_V250922.…
KEV: CVE-2026-84869 — ConnectWise ScreenConnect (ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability)
CVE. Sourced from kev, summarised by Matproof.
AI Analysis
What changed and what to do.
CISA added CVE-2026-84869, an improper privilege management and missing authorization flaw in ConnectWise ScreenConnect, to its Known Exploited Vulnerabilities catalog on 11 September 2026. The vulnerability allows an authenticated attacker to escalate privileges or bypass authorization controls, and active exploitation in the wild has been confirmed. Federal agencies subject to Binding Operational Directive 22-01 must remediate by the mandated deadline; the KEV listing also signals elevated risk for all other organizations.
ScreenConnect is widely used for remote support and endpoint management, so exposure extends across managed service providers, healthcare, finance, government contractors, and any organization relying on third-party IT support. Because MSPs often hold privileged access to client environments, a compromise can cascade across multiple downstream organizations, making supply chain exposure a key concern.
Compliance teams should immediately confirm whether ScreenConnect is deployed, check versions against vendor guidance, and apply patches or mitigations without delay. Review access logs for signs of exploitation, verify that least-privilege and MFA controls are enforced, and assess contractual obligations to notify clients or regulators if a breach is suspected. Document remediation steps and timelines to evidence compliance with vulnerability management requirements under NIS2, DORA, or ISO 27001, and monitor the KEV catalog for updates.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
More CVE updates
Latest in CVE.
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.