ConnectWise patched a critical ScreenConnect vulnerability, CVE-2026-3564. The flaw could expose ASP.NET machine keys and enable unauthorized session authentication and privilege escalation. Elastic Security Labs found an active SILENTCONNECT loader that delivers ScreenConnect via multistage VBScript and in-memory PowerShell, enabling hands-on access to infected hosts.
Part of the PlainSec briefing for 2026-03-22