logo

Unpatched ScreenConnect servers open to attack (CVE-2026-3564)

ID: c857f183-55cb-58d7-98cc-ab51fe492553

STIX ID: report--c857f183-55cb-58d7-98cc-ab51fe492553

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-03-20

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

ConnectWise patched CVE-2026-3564, a critical vulnerability in ScreenConnect that allowed unauthenticated remote attackers to forge session authentication by abusing stored ASP.NET machine keys; the issue affects all ScreenConnect versions before 26.1, could enable unauthorized administrative actions and remote access to managed devices, and customers are urged to upgrade to v26.1 and review logs and access controls—ConnectWise reports no confirmed exploitation to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.