CVE-2026-3564
CVSS 9 CRITICAL: a condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for… EPSS 0.4% (28th percentile).
Vulnerabilities & Exploits
The flaw can expose ASP.NET machine keys and allow attackers to forge session values for unauthorized access and privilege escalation. Elastic Security Labs observed a SILENTCONNECT loader delivering ScreenConnect via VBScript and in-memory PowerShell, enabling hands-on access on infected hosts.
4 sources · Mar 20
CVSS 9 CRITICAL: a condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for… EPSS 0.4% (28th percentile).
Help Net Security
Unpatched ScreenConnect servers open to attack (CVE-2026-3564) - Help Net Security
ConnectWise has patched a critical vulnerability (CVE-2026-3564) that could enable attackers to hijack ScreenConnect sessions.
originalSecurityWeek
Critical ScreenConnect Vulnerability Exposes Machine Keys
Latest ScreenConnect version adds encrypted storage and management to prevent unauthorized access to machine keys.
originalElastic Security Labs
From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect — Elastic Security Labs
SILENTCONNECT is a multi-stage loader that leverages VBScript, in-memory PowerShell execution, and PEB masquerading to silently deploy the ScreenConnect RMM tool.
originalPart of the PlainSec briefing for 2026-03-19
Every edition of this story: Critical ScreenConnect Flaw and SILENTCONNECT Loader Observed