Unpatched ScreenConnect servers open to attack (CVE-2026-3564)
ID: c857f183-55cb-58d7-98cc-ab51fe492553
STIX ID: report--c857f183-55cb-58d7-98cc-ab51fe492553
Feed Name: Help Net Security
Threat Score
ConnectWise patched CVE-2026-3564, a critical vulnerability in ScreenConnect that allowed unauthenticated remote attackers to forge session authentication by abusing stored ASP.NET machine keys; the issue affects all ScreenConnect versions before 26.1, could enable unauthorized administrative actions and remote access to managed devices, and customers are urged to upgrade to v26.1 and review logs and access controls—ConnectWise reports no confirmed exploitation to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
