Vulnerabilities · 179 days ago

ScreenConnect Machine-Key Flaw and SILENTCONNECT Loader

ConnectWise patched a critical ScreenConnect vulnerability, CVE-2026-3564. The flaw could expose ASP.NET machine keys and enable unauthorized session authentication and privilege escalation. Elastic Security Labs found an active SILENTCONNECT loader that delivers ScreenConnect via multistage VBScript and in-memory PowerShell, enabling hands-on access to infected hosts.

CVE-2026-3564

NVD KEV

CVSS 9 CRITICAL: a condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for… EPSS 0.4% (28th percentile).

Timeline

Sources

4 sources covering this story

Entities

Part of the PlainSec briefing for 2026-03-22

Editions

Related stories