CVE-2026-3564
CVSS 9 CRITICAL: a condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for… EPSS 0.3% (19º percentile).
Vulnerabilità ed exploit
La vulnerabilità di cryptographic signature verification può esporre gli ASP.NET machine keys e permettere autenticazione di sessioni non autorizzate e escalation di privilegi. Elastic Security Labs ha osservato il loader SILENTCONNECT che, tramite VBScript multistage e in-memory PowerShell, distribuisce ScreenConnect e abilita hands-on access su host compromessi.
4 fonti · 20 mar
CVSS 9 CRITICAL: a condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for… EPSS 0.3% (19º percentile).
Help Net Security
Unpatched ScreenConnect servers open to attack (CVE-2026-3564) - Help Net Security
ConnectWise has patched a critical vulnerability (CVE-2026-3564) that could enable attackers to hijack ScreenConnect sessions.
originaleSecurityWeek
Critical ScreenConnect Vulnerability Exposes Machine Keys
Latest ScreenConnect version adds encrypted storage and management to prevent unauthorized access to machine keys.
originaleElastic Security Labs
From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect — Elastic Security Labs
SILENTCONNECT is a multi-stage loader that leverages VBScript, in-memory PowerShell execution, and PEB masquerading to silently deploy the ScreenConnect RMM tool.
originalePart of the PlainSec briefing for 2026-03-20
Every edition of this story: ScreenConnect vulnerabile, SILENTCONNECT abilita accesso non autorizzato