logo

ScreenConnect Vulnerability Allows Hackers to Extract Unique Machine Keys and Hijack Sessions

ID: 53a2c007-8381-5be8-84cf-63404df7e672

STIX ID: report--53a2c007-8381-5be8-84cf-63404df7e672

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-18

Date Updated: 2026-04-21

Author: Guru Baran

...
...

ConnectWise has disclosed a critical cryptographic vulnerability (CVE-2026-3564, CVSS 9.0) in ScreenConnect versions prior to 26.1 where server machine keys were stored in plaintext in configuration files, allowing unauthenticated attackers with access to filesystem/config data to extract keys and forge session authentication; scope is changed and ConnectWise rates it Priority 1. Cloud-hosted instances are mitigated, but on-premises deployments must urgently upgrade to 26.1 (which adds encrypted key storage) and audit authentication logs for signs of exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.