THE MSP TOOL THAT BECAME THE MSP BREACH

ConnectWise ScreenConnect — remote support software used by managed service providers to administer hundreds or thousands of customer endpoints — has been actively exploited since August 20 via CVE-2026-84869, a CVSS 9.9 authentication bypass (ConnectWise assessment, disclosed September 8, 2026), which means 19 days of exploitation before public warning.

The vulnerability allows attackers to transfer files through active remote sessions and execute them without authorization or host confirmation. Missing authorization check during file transfer operations. An attacker injects commands into an existing support session, pushes malware, runs it. Silent compromise through a trusted channel.

MSPs use ScreenConnect for legitimate troubleshooting, software installation, configuration work. Users trust technicians with that access. CVE-2026-84869 abuses the trust: the attack looks like authorized remote support until the backdoor deploys.

This is the second major ConnectWise exploitation event in eight months. February 2024: CVE-2024-1708 and CVE-2024-1709, authentication bypass and remote code execution, exploited by LockBit affiliates and other ransomware groups within hours of disclosure. Mass exploitation, MSP customer compromises, emergency patching.

The file transfer plus execution capability is purpose-built for ransomware deployment. Attacker pushes the binary to every endpoint the MSP manages, executes simultaneously across the customer base. Kaseya VSA precedent: July 2021, REvil ransomware exploited VSA vulnerability, fewer than 1,500 downstream businesses affected per Kaseya's July 2021 statement, $70 million ransom demanded by REvil — roughly the annual operating budget of a small American city.

ConnectWise offers on-premises and cloud-hosted versions. Cloud instances ConnectWise patches centrally. On-premises installations require customers to patch themselves — testing, deployment, coordination, downtime. That's where the lag lives. The 19-day window from August 20 to September 8 is how long attackers had before the public warning. Victims compromised during that window remain at risk even after patching if backdoors persist.

Forensic investigation requires reviewing ScreenConnect session logs, file transfer records, command history, endpoint file writes and executions. But attackers tamper with logs, delete evidence. Requires centralized log shipping to a SIEM before the compromise, otherwise the artifacts disappear with the attacker.

Endpoint detection and response tools may catch suspicious file writes or execution from the ScreenConnect process, but trusted software evades signature-based detection. Behavioral analysis — ScreenConnect child processes, unusual network connections, privilege escalation — provides better visibility, but sophisticated actors use living-off-the-land techniques that blend with legitimate admin activity.

MSPs compromised via ScreenConnect lose the ability to support customers. The remote access tool itself is the breach vector. Rebuilding trust, forensic investigation across the entire customer portfolio, breach notifications, contractual liability, SLA violations. Reputational damage that drives customers to competitors.

Cyber insurance covers MSP errors and omissions, cyber liability for customer breaches. But premiums are rising, coverage limits shrinking, policy exclusions expanding post-Kaseya. Insurers now require security controls like multi-factor authentication, privileged access management, rapid patching discipline. An unpatched CVE-2026-84869 exploitation might trigger a coverage dispute — was the vulnerability known, was patching reasonably prompt, did the MSP meet its duty of care.

Customer contracts increasingly specify cybersecurity requirements, audit rights, breach notification timelines, liability caps. MSPs face legal exposure when customer data is exfiltrated or encrypted via a compromised ScreenConnect instance. Class actions, regulatory investigations by state attorneys general and the FTC.

ConnectWise issued an emergency advisory, patch, customer notifications. The MSP customer base represents thousands of service providers. Webinars, technical guidance, patch urgency communications. But the 19-day exploitation window already burned the customers who didn't patch immediately — and many on-premises deployments lag weeks behind due to testing and change management processes.

The pattern: Kaseya VSA in 2021. ConnectWise ScreenConnect in February 2024. ConnectWise again in August 2026. MSP tools are high-value targets because a single compromise yields access to hundreds of downstream organizations. The supply chain economics make MSP software exploitation more lucrative than individual enterprise targeting.

Zero-trust remote access architectures — continuous authentication, least privilege, session monitoring — raise the bar. But legacy remote support tools built on trust models from a different threat landscape remain deployed at scale. CVE-2026-84869 is what happens when that trust model meets an authentication bypass.

ConnectWise customers are evaluating alternatives: TeamViewer, AnyDesk, LogMeIn, BeyondTrust, Dameware. Market dynamics shift when a platform has repeated exploitation events. Contract renewals, competitive bids, switching costs vs. breach risk.

August 20 to September 8. 19 days. How many MSPs were hit, how many of their customers were compromised, what was exfiltrated or encrypted — those disclosures come later, in breach notifications, regulatory filings, earnings calls. The public disclosure is the start of the investigation, not the end.

The file transfer logs will tell the story. If they still exist.