CVE-2026-3564
ScreenConnect Server vulnerability analysis and mitigation

Overview

CVE-2026-3564 is a critical cryptographic vulnerability in ConnectWise ScreenConnect that may allow an actor with access to server-level cryptographic material to obtain unauthorized access, including elevated privileges. It was published on March 17, 2026, and affects all ScreenConnect versions prior to 26.1. The vulnerability is classified as CWE-347 (Improper Verification of Cryptographic Signature) and carries a CVSS v3.1 base score of 9.0 (Critical) (ConnectWise Bulletin, ENISA EUVD).

Technical details

The root cause lies in how earlier versions of ScreenConnect stored unique ASP.NET machine keys per instance in plaintext within server configuration files (CWE-347). Under certain conditions — such as when an attacker gains read access to the server's file system or configuration — these machine keys could be extracted and subsequently abused to forge authenticated session tokens, bypassing authentication controls entirely. ScreenConnect 26.1 addresses this by introducing encrypted storage and management of machine keys, reducing the risk of key extraction even if server integrity is partially compromised (ConnectWise Bulletin, BleepingComputer, Bulwark Black). A Nuclei detection template was submitted to the ProjectDiscovery community repository, indicating growing tooling interest (Nuclei Templates PR).

Impact

Successful exploitation allows an attacker to forge valid session authentication tokens, enabling unauthorized access to ScreenConnect with potentially elevated privileges — including full administrative control over managed remote sessions. The scope is marked as "Changed" in the CVSS vector, meaning a compromise of the ScreenConnect server can cascade to all connected endpoints managed through the platform, enabling lateral movement across the entire managed device estate. Confidentiality, integrity, and availability are all rated HIGH, reflecting the potential for complete system compromise, data exfiltration, and disruption of remote access services (ConnectWise Bulletin, CyberSecurityNews).

Exploitability

As of the time of reporting, no public proof-of-concept exploit code has been confirmed, and there is no verified evidence of active in-the-wild exploitation (Feedly Intelligence). However, ConnectWise assigned this a Priority 1 (High) rating, indicating the vulnerability is either being targeted or has a higher risk of being targeted by exploits in the wild. The EPSS score is approximately 0.046% (0.000460), reflecting a currently low but non-negligible probability of exploitation. The vulnerability is not listed in the CISA KEV catalog at this time. A Nuclei template pull request was submitted, suggesting active community interest in detection and potential weaponization (Nuclei Templates PR, Recorded Future).

Exploitation steps

  1. Reconnaissance: Identify internet-facing ScreenConnect on-premises instances running versions prior to 26.1 using tools like Shodan or Censys, or by probing the ScreenConnect web interface for version banners.
  2. Gain access to server configuration: Obtain read access to the ScreenConnect server's file system or configuration files — this may be achieved via a separate vulnerability (e.g., path traversal, misconfigured file permissions, or compromised server credentials).
  3. Extract machine keys: Locate and read the ASP.NET machine key values stored in plaintext within ScreenConnect's server configuration files (e.g., web.config or equivalent).
  4. Forge authentication tokens: Use the extracted machine keys to craft valid, signed ASP.NET ViewState or authentication tokens that ScreenConnect will accept as legitimate.
  5. Achieve unauthorized access: Submit the forged tokens to the ScreenConnect server to authenticate as a privileged user, gaining administrative control over the ScreenConnect instance and all managed remote sessions (ConnectWise Bulletin, BleepingComputer, Bulwark Black).

Indicators of compromise

  • File System: Unexpected read access or modification timestamps on ScreenConnect configuration files (e.g., web.config); presence of scripts or tools designed to parse ASP.NET machine keys on the server.
  • Logs: ScreenConnect access logs showing authentication events from unexpected IP addresses or at unusual times; forged session tokens appearing in application logs that do not correspond to legitimate user login flows.
  • Network: Outbound connections from the ScreenConnect server to unknown external IPs; unusual administrative actions (e.g., new user creation, session initiation to many endpoints) originating from unexpected source addresses.
  • Process: Unexpected processes spawned under the ScreenConnect service account; file enumeration or configuration file access by non-standard processes (BleepingComputer, CyberSecurityNews).

Mitigation and workarounds

ConnectWise has released ScreenConnect version 26.1, which introduces encrypted storage and management of machine keys, directly addressing the vulnerability. On-premises ScreenConnect partners should upgrade to version 26.1 immediately via the official download page; cloud-hosted instances require no action as they were patched automatically. As interim measures, organizations should restrict file system access to ScreenConnect configuration files, implement network segmentation to limit exposure of ScreenConnect servers, and audit authentication logs for anomalous access patterns (ConnectWise Bulletin).

Community reactions

ConnectWise assigned the vulnerability a Priority 1 (High) rating and recommended treating the patch as an emergency change, signaling urgency to its partner base (ConnectWise Bulletin). The Belgian Centre for Cybersecurity (CCB) issued a warning urging immediate patching, and the UK NHS also published a cyber alert (CCB Advisory, NHS Cyber Alert). Community discussion on Reddit's r/msp and r/sysadmin subreddits was active, with administrators comparing it to other recent high-severity CVEs and discussing urgency of patching. Security media including BleepingComputer, HelpNet Security, and The Hacker News covered the vulnerability in weekly recaps, reflecting broad industry attention (BleepingComputer, HelpNet Security).

Additional resources


SourceThis report was generated using AI

Related ScreenConnect Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14265CRITICAL9.1
  • ScreenConnect Server logoScreenConnect Server
  • cpe:2.3:a:connectwise:screenconnect
NoYesDec 11, 2025
CVE-2026-3564CRITICAL9
  • ScreenConnect Server logoScreenConnect Server
  • cpe:2.3:a:connectwise:screenconnect
NoYesMar 17, 2026
CVE-2025-3935HIGH7.2
  • ScreenConnect Server logoScreenConnect Server
  • cpe:2.3:a:connectwise:screenconnect
YesYesApr 25, 2025
CVE-2025-14823MEDIUM5.3
  • ScreenConnect Server logoScreenConnect Server
  • cpe:2.3:a:connectwise:screenconnect
NoYesDec 18, 2025
CVE-2026-11596MEDIUM4.7
  • ScreenConnect Server logoScreenConnect Server
  • cpe:2.3:a:connectwise:screenconnect
NoYesJun 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management