CVE-2026-3564
CVSS 9 CRITICAL: a condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for… EPSS 0.4% (28th percentile).
Vulnerabilities · 179 days ago
ConnectWise patched a critical ScreenConnect vulnerability, CVE-2026-3564. The flaw could expose ASP.NET machine keys and enable unauthorized session authentication and privilege escalation. Elastic Security Labs found an active SILENTCONNECT loader that delivers ScreenConnect via multistage VBScript and in-memory PowerShell, enabling hands-on access to infected hosts.
CVSS 9 CRITICAL: a condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for… EPSS 0.4% (28th percentile).
4 sources covering this story
Unpatched ScreenConnect servers open to attack (CVE-2026-3564) - Help Net Security
ConnectWise has patched a critical vulnerability (CVE-2026-3564) that could enable attackers to hijack ScreenConnect sessions.
Critical ScreenConnect Vulnerability Exposes Machine Keys
Latest ScreenConnect version adds encrypted storage and management to prevent unauthorized access to machine keys.
From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect — Elastic Security Labs
SILENTCONNECT is a multi-stage loader that leverages VBScript, in-memory PowerShell execution, and PEB masquerading to silently deploy the ScreenConnect RMM tool.
ConnectWise patches new flaw allowing ScreenConnect hijacking
ConnectWise is warning ScreenConnect customers of a cryptographic signature verification vulnerability that could lead to unauthorized access and privilege escalation.
Part of the PlainSec briefing for 2026-03-22