CVE-2026-84869: ConnectWise ScreenConnect
ConnectWise ScreenConnect에는 improper 특권 관리 및 누락 된 권한 취약점이 포함되어 있습니다. 공격자는 권한 또는 호스트 확인없이 활성 원격 세션을 통해 파일을 전송하고 실행할 수 있습니다.
CISA (English)
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.
- 공급업체
- ConnectWise
- 제품
- ScreenConnect
- 취약점
- ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- 추가일
- 2026. 9. 11.
- CISA 조치 기한(미국 연방기관)
- 2026. 9. 14.
- 랜섬웨어 공격 악용
- 알 수 없음
- 약점(CWE)
- CWE-269, CWE-862
참고 자료
이 사이트는 정보 제공 목적으로 CISA 카탈로그를 요약한 것이며 보안 조언이 아닙니다. 공급업체 안내와 공식 권고를 따르세요.
최종 업데이트: · 카탈로그 버전 2026.10.02