logo

Leaving the Doors Unlocked: Critical 9.0 CVSS ScreenConnect Flaw Exposes Machine Keys

ID: 47a9856d-6425-5443-b3ed-d1a0c3dad945

STIX ID: report--47a9856d-6425-5443-b3ed-d1a0c3dad945

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-04-23

Author: Ddos

...
...

ConnectWise issued a critical security update for ScreenConnect addressing CVE-2026-3564, a severe vulnerability (CVSS 9.0) in which unique machine keys were stored in server configuration files and could be extracted by attackers to impersonate sessions and fully compromise systems; cloud instances are updated by ConnectWise, while on-premise installations must upgrade immediately to version 26.1 which adds encrypted storage and management for machine keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.