logo

ScreenConnect Flaw Lets Hackers Steal Machine Keys and Hijack Sessions

ID: 50d6fb2f-f551-5403-b584-fac49a79007c

STIX ID: report--50d6fb2f-f551-5403-b584-fac49a79007c

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-03-19

Date Updated: 2026-04-22

Author: Divya

...
...

ConnectWise issued a Priority 1 security bulletin for CVE-2026-3564, a critical CWE-347 flaw in ScreenConnect that allows attackers to extract machine keys from server configuration, forge session authentication, and hijack remote sessions (CVSS 9.0). ConnectWise released ScreenConnect 26.1 with encrypted key storage and active key management; cloud instances have been patched, while on-premise administrators must urgently apply the update (or renew maintenance to obtain it).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.