
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3564 is a critical cryptographic vulnerability in ConnectWise ScreenConnect that may allow an actor with access to server-level cryptographic material to obtain unauthorized access, including elevated privileges. It was published on March 17, 2026, and affects all ScreenConnect versions prior to 26.1. The vulnerability is classified as CWE-347 (Improper Verification of Cryptographic Signature) and carries a CVSS v3.1 base score of 9.0 (Critical) (ConnectWise Bulletin, ENISA EUVD).
The root cause lies in how earlier versions of ScreenConnect stored unique ASP.NET machine keys per instance in plaintext within server configuration files (CWE-347). Under certain conditions — such as when an attacker gains read access to the server's file system or configuration — these machine keys could be extracted and subsequently abused to forge authenticated session tokens, bypassing authentication controls entirely. ScreenConnect 26.1 addresses this by introducing encrypted storage and management of machine keys, reducing the risk of key extraction even if server integrity is partially compromised (ConnectWise Bulletin, BleepingComputer, Bulwark Black). A Nuclei detection template was submitted to the ProjectDiscovery community repository, indicating growing tooling interest (Nuclei Templates PR).
Successful exploitation allows an attacker to forge valid session authentication tokens, enabling unauthorized access to ScreenConnect with potentially elevated privileges — including full administrative control over managed remote sessions. The scope is marked as "Changed" in the CVSS vector, meaning a compromise of the ScreenConnect server can cascade to all connected endpoints managed through the platform, enabling lateral movement across the entire managed device estate. Confidentiality, integrity, and availability are all rated HIGH, reflecting the potential for complete system compromise, data exfiltration, and disruption of remote access services (ConnectWise Bulletin, CyberSecurityNews).
As of the time of reporting, no public proof-of-concept exploit code has been confirmed, and there is no verified evidence of active in-the-wild exploitation (Feedly Intelligence). However, ConnectWise assigned this a Priority 1 (High) rating, indicating the vulnerability is either being targeted or has a higher risk of being targeted by exploits in the wild. The EPSS score is approximately 0.046% (0.000460), reflecting a currently low but non-negligible probability of exploitation. The vulnerability is not listed in the CISA KEV catalog at this time. A Nuclei template pull request was submitted, suggesting active community interest in detection and potential weaponization (Nuclei Templates PR, Recorded Future).
web.config or equivalent).web.config); presence of scripts or tools designed to parse ASP.NET machine keys on the server.ConnectWise has released ScreenConnect version 26.1, which introduces encrypted storage and management of machine keys, directly addressing the vulnerability. On-premises ScreenConnect partners should upgrade to version 26.1 immediately via the official download page; cloud-hosted instances require no action as they were patched automatically. As interim measures, organizations should restrict file system access to ScreenConnect configuration files, implement network segmentation to limit exposure of ScreenConnect servers, and audit authentication logs for anomalous access patterns (ConnectWise Bulletin).
ConnectWise assigned the vulnerability a Priority 1 (High) rating and recommended treating the patch as an emergency change, signaling urgency to its partner base (ConnectWise Bulletin). The Belgian Centre for Cybersecurity (CCB) issued a warning urging immediate patching, and the UK NHS also published a cyber alert (CCB Advisory, NHS Cyber Alert). Community discussion on Reddit's r/msp and r/sysadmin subreddits was active, with administrators comparing it to other recent high-severity CVEs and discussing urgency of patching. Security media including BleepingComputer, HelpNet Security, and The Hacker News covered the vulnerability in weekly recaps, reflecting broad industry attention (BleepingComputer, HelpNet Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."