CVE-2026-84869: ConnectWise ScreenConnect
ConnectWise ScreenConnect は、不正な権限管理と不正な権限の脆弱性の両方が含まれているため、攻撃者が承認やホストの確認なしに、アクティブなリモートセッションを通じてファイルを転送および実行できます。
CISA (English)
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.
- ベンダー
- ConnectWise
- 製品
- ScreenConnect
- 脆弱性
- ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- 追加日
- 2026/09/11
- CISA対応期限(米国連邦機関向け)
- 2026/09/14
- ランサムウェア攻撃での利用
- 不明
- 弱点(CWE)
- CWE-269, CWE-862
参考情報
当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。
最終更新: · カタログのバージョン 2026.10.02