CVE-2026-3564
CVSS 9 CRITICAL: a condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for… EPSS 0.3% (19º percentile).
Vulnerabilità ed exploit
La falla può esporre gli ASP.NET machine keys e permettere la generazione di sessioni contraffatte per accesso non autorizzato e possibile escalation di privilegi. Elastic Security Labs ha osservato il loader SILENTCONNECT che distribuisce ScreenConnect tramite VBScript e PowerShell in-memory, abilitando hands-on keyboard sui sistemi compromessi.
4 fonti · 20 mar
CVSS 9 CRITICAL: a condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for… EPSS 0.3% (19º percentile).
Help Net Security
Unpatched ScreenConnect servers open to attack (CVE-2026-3564) - Help Net Security
ConnectWise has patched a critical vulnerability (CVE-2026-3564) that could enable attackers to hijack ScreenConnect sessions.
originaleSecurityWeek
Critical ScreenConnect Vulnerability Exposes Machine Keys
Latest ScreenConnect version adds encrypted storage and management to prevent unauthorized access to machine keys.
originaleElastic Security Labs
From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect — Elastic Security Labs
SILENTCONNECT is a multi-stage loader that leverages VBScript, in-memory PowerShell execution, and PEB masquerading to silently deploy the ScreenConnect RMM tool.
originalePart of the PlainSec briefing for 2026-03-19
Every edition of this story: Falla critica in ScreenConnect e loader SILENTCONNECT osservati