ConnectWise patches new flaw allowing ScreenConnect hijacking
ID: bfab722b-f941-5d91-8ccc-8f5d4f09cc96
STIX ID: report--bfab722b-f941-5d91-8ccc-8f5d4f09cc96
Feed Name: Bleeping Computer
ConnectWise disclosed a critical cryptographic signature verification vulnerability (CVE-2026-3564) in ScreenConnect that can allow extraction and misuse of ASP.NET machine keys to forge sessions and gain unauthorized access; the vendor released fixes in ScreenConnect 26.1 (cloud users auto-upgraded) and urges on‑prem administrators to upgrade and harden secrets, while noting researchers observed attempts to abuse disclosed machine key material but there is no confirmed evidence the specific CVE has been exploited in the vendor-hosted service.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
