ScreenConnect Vulnerability Allows Hackers to Extract Unique Machine Keys and Hijack Sessions
ID: 53a2c007-8381-5be8-84cf-63404df7e672
STIX ID: report--53a2c007-8381-5be8-84cf-63404df7e672
Feed Name: cybersecurityNews.com
ConnectWise has disclosed a critical cryptographic vulnerability (CVE-2026-3564, CVSS 9.0) in ScreenConnect versions prior to 26.1 where server machine keys were stored in plaintext in configuration files, allowing unauthenticated attackers with access to filesystem/config data to extract keys and forge session authentication; scope is changed and ConnectWise rates it Priority 1. Cloud-hosted instances are mitigated, but on-premises deployments must urgently upgrade to 26.1 (which adds encrypted key storage) and audit authentication logs for signs of exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
