Vulnerabilities & Exploits

Critical ScreenConnect Flaw and SILENTCONNECT Loader Observed

The flaw can expose ASP.NET machine keys and allow attackers to forge session values for unauthorized access and privilege escalation. Elastic Security Labs observed a SILENTCONNECT loader delivering ScreenConnect via VBScript and in-memory PowerShell, enabling hands-on access on infected hosts.

4 sources · Mar 20

CVE-2026-3564

NVD KEV

CVSS 9 CRITICAL: a condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for… EPSS 0.4% (28th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-03-19

Every edition of this story: Critical ScreenConnect Flaw and SILENTCONNECT Loader Observed

More from today