Vulnerabilità · 193 giorni fa

ScreenConnect Machine-Key Flaw and SILENTCONNECT Loader

ConnectWise patched a critical ScreenConnect vulnerability, CVE-2026-3564. The flaw could expose ASP.NET machine keys and enable unauthorized session authentication and privilege escalation. Elastic Security Labs found an active SILENTCONNECT loader that delivers ScreenConnect via multistage VBScript and in-memory PowerShell, enabling hands-on access to infected hosts.

CVE-2026-3564

NVD KEV

CVSS 9 CRITICAL: a condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for… EPSS 0.3% (19º percentile).

Cronologia

Fonti

4 fonti che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-03-22

Editions

Storie correlate