Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Pokémon Center Data Breach Exposes Customer PII to Hackers
August 18, 2026
Best Software-Defined Perimeter (SDP) Solutions of 2024
August 17, 2026
Threema Messaging Service Suffers Massive DDoS Attack
August 17, 2026
Home/CyberSecurity News/Critical ScreenConnect Vulnerability Lets Attackers Extract Keys, Hijack Sessions
CyberSecurity News

Critical ScreenConnect Vulnerability Lets Attackers Extract Keys, Hijack Sessions

Key Takeaways A critical cryptographic flaw in ConnectWise ScreenConnect allows attackers to extract server keys. The vulnerability, CVE-2026-3564, affects all on-premises ScreenConnect versions...

Jennifer sherman
Jennifer sherman
March 18, 2026 3 Min Read
53 0

Key Takeaways

  • A critical cryptographic flaw in ConnectWise ScreenConnect allows attackers to extract server keys.
  • The vulnerability, CVE-2026-3564, affects all on-premises ScreenConnect versions before 26.1 and carries a CVSS score of 9.0.
  • Successful exploitation could lead to session hijacking and impersonation without authentication.
  • ConnectWise has released ScreenConnect version 26.1 to patch the flaw; on-premises users must update immediately.

ConnectWise has issued an urgent security bulletin concerning a critical vulnerability within its widely used ScreenConnect remote desktop software. This significant cryptographic flaw enables unauthenticated attackers to extract sensitive server-level machine keys, potentially leading to the hijacking of legitimate user sessions.

Table Of Content

  • Key Takeaways
  • Understanding the Vulnerability
  • Immediate Action Required for On-Premises Deployments
  • What You Should Do

Designated as CVE-2026-3564, the vulnerability impacts all ScreenConnect installations preceding version 26.1. It has been assigned a CVSS score of 9.0, placing it squarely in the critical severity category.

Understanding the Vulnerability

The core of the problem lies in how earlier iterations of ScreenConnect managed and stored unique machine keys and cryptographic identifiers associated with each server instance. These vital cryptographic elements were stored in plaintext within server configuration files.

This insecure storage mechanism means that an attacker who manages to gain access to the server’s filesystem or configuration data could extract these machine keys without requiring elevated administrative privileges on the compromised system. Once an attacker obtains these keys, they can be leveraged to forge or manipulate session authentication tokens, effectively allowing them to impersonate legitimate users and bypass existing access controls.

The flaw is categorized under CWE-347 (Improper Verification of Cryptographic Signature). This classification points to the software’s failure to adequately validate the integrity of these critical cryptographic components before relying on them for authentication decisions.

The CVSS vector further highlights the severity, indicating that the vulnerability is network-exploitable, requires no privileges, and demands no user interaction. However, the “high attack complexity” rating suggests that specific conditions must be met for a successful exploit. Notably, the scope is marked as “Changed,” implying that a successful breach could affect resources beyond the directly vulnerable component, a significant concern for enterprise environments heavily reliant on ScreenConnect for remote access.

Immediate Action Required for On-Premises Deployments

ConnectWise has assigned this vulnerability a Priority 1 (High) rating, signifying an elevated risk of active exploitation in the wild. Organizations utilizing on-premises ScreenConnect deployments are particularly exposed and should treat remediation as an emergency. ConnectWise advises patching within days of the advisory’s release.

The newly released ScreenConnect version 26.1 addresses this flaw by implementing encrypted storage and enhanced key management practices for machine key material. This significant improvement substantially reduces the risk of unauthorized extraction, even if a server’s integrity is partially compromised.

Users of cloud-hosted ScreenConnect instances are not required to take any action, as ConnectWise has already applied the necessary mitigations on its backend. However, partners managing on-premises deployments must manually upgrade their installations to version 26.1. This update can be obtained through the official ScreenConnect download page. It is important to note that any lapsed maintenance licenses must be renewed before the update can be applied.

What You Should Do

  • Immediately upgrade all on-premises ConnectWise ScreenConnect installations to version 26.1.
  • Ensure all maintenance licenses are current before attempting the upgrade.
  • Audit session logs for any unusual or anomalous authentication activity that could indicate prior exploitation attempts.
  • Review your overall remote access security posture and ensure multi-factor authentication is enforced where possible.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitHackerPatchSecurityVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

SolarWinds Serv-U Critical RCE Bug CVE-2024-28925 Lets Attackers Gain Root Access

Next Post

Critical Telnetd CVE-2024-XXXXX lets attackers run code via port 23

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Microsoft SCCM Vulnerability Lets Attackers Execute Remote Code
August 17, 2026
Z.ai Launches GLM-5.3, Boosting Cybersecurity and Coding Capabilities
August 17, 2026
Critical GeoServer SQLi Vulnerability Allows Remote Code Execution
August 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us