Critical ScreenConnect Vulnerability Lets Attackers Extract Keys, Hijack Sessions
Key Takeaways A critical cryptographic flaw in ConnectWise ScreenConnect allows attackers to extract server keys. The vulnerability, CVE-2026-3564, affects all on-premises ScreenConnect versions...
Key Takeaways
- A critical cryptographic flaw in ConnectWise ScreenConnect allows attackers to extract server keys.
- The vulnerability, CVE-2026-3564, affects all on-premises ScreenConnect versions before 26.1 and carries a CVSS score of 9.0.
- Successful exploitation could lead to session hijacking and impersonation without authentication.
- ConnectWise has released ScreenConnect version 26.1 to patch the flaw; on-premises users must update immediately.
ConnectWise has issued an urgent security bulletin concerning a critical vulnerability within its widely used ScreenConnect remote desktop software. This significant cryptographic flaw enables unauthenticated attackers to extract sensitive server-level machine keys, potentially leading to the hijacking of legitimate user sessions.
Table Of Content
Designated as CVE-2026-3564, the vulnerability impacts all ScreenConnect installations preceding version 26.1. It has been assigned a CVSS score of 9.0, placing it squarely in the critical severity category.
Understanding the Vulnerability
The core of the problem lies in how earlier iterations of ScreenConnect managed and stored unique machine keys and cryptographic identifiers associated with each server instance. These vital cryptographic elements were stored in plaintext within server configuration files.
This insecure storage mechanism means that an attacker who manages to gain access to the server’s filesystem or configuration data could extract these machine keys without requiring elevated administrative privileges on the compromised system. Once an attacker obtains these keys, they can be leveraged to forge or manipulate session authentication tokens, effectively allowing them to impersonate legitimate users and bypass existing access controls.
The flaw is categorized under CWE-347 (Improper Verification of Cryptographic Signature). This classification points to the software’s failure to adequately validate the integrity of these critical cryptographic components before relying on them for authentication decisions.
The CVSS vector further highlights the severity, indicating that the vulnerability is network-exploitable, requires no privileges, and demands no user interaction. However, the “high attack complexity” rating suggests that specific conditions must be met for a successful exploit. Notably, the scope is marked as “Changed,” implying that a successful breach could affect resources beyond the directly vulnerable component, a significant concern for enterprise environments heavily reliant on ScreenConnect for remote access.
Immediate Action Required for On-Premises Deployments
ConnectWise has assigned this vulnerability a Priority 1 (High) rating, signifying an elevated risk of active exploitation in the wild. Organizations utilizing on-premises ScreenConnect deployments are particularly exposed and should treat remediation as an emergency. ConnectWise advises patching within days of the advisory’s release.
The newly released ScreenConnect version 26.1 addresses this flaw by implementing encrypted storage and enhanced key management practices for machine key material. This significant improvement substantially reduces the risk of unauthorized extraction, even if a server’s integrity is partially compromised.
Users of cloud-hosted ScreenConnect instances are not required to take any action, as ConnectWise has already applied the necessary mitigations on its backend. However, partners managing on-premises deployments must manually upgrade their installations to version 26.1. This update can be obtained through the official ScreenConnect download page. It is important to note that any lapsed maintenance licenses must be renewed before the update can be applied.
What You Should Do
- Immediately upgrade all on-premises ConnectWise ScreenConnect installations to version 26.1.
- Ensure all maintenance licenses are current before attempting the upgrade.
- Audit session logs for any unusual or anomalous authentication activity that could indicate prior exploitation attempts.
- Review your overall remote access security posture and ensure multi-factor authentication is enforced where possible.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.