ConnectWise ScreenConnect disclosed a critical vulnerability, CVE-2026-3564 (CVSS 9.0), affecting versions prior to 26.1. The flaw stems from ScreenConnect storing unique per-instance machine keys and related cryptographic material in plaintext server configuration files, creating a path for attackers under certain conditions to extract those keys and abuse them for unauthorized access. The issue is classified as CWE-347: Improper Verification of Cryptographic Signature, and successful exploitation can undermine confidentiality, integrity, and availability in environments that rely on ScreenConnect for remote access.
With the exposed machine keys, an attacker could forge or manipulate session authentication tokens, hijack legitimate sessions, and elevate access without user interaction. ConnectWise rated the issue as high priority, and the Centre for Cybersecurity Belgium urged organizations to patch immediately, monitor for suspicious activity, and treat updates as protection against future exploitation rather than proof that no prior compromise occurred. The vendor states the issue is fixed in version 26.1, making rapid remediation and post-patch review important for on-premises deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In guidance reflected by CSIRT.SK on March 19, 2026, ConnectWise said it had observed exploitation attempts targeting the critical ScreenConnect flaw CVE-2026-3564. The company reiterated that vulnerable versions earlier than 26.1 should be upgraded immediately, while cloud-hosted instances were automatically secured.
On March 18, 2026, government cybersecurity bodies including Belgium's CCB and Canada's Cyber Centre amplified ConnectWise's advisory and urged organizations to review guidance and apply the 26.1 update promptly. Their notices highlighted the severity of the issue for ScreenConnect deployments prior to version 26.1.
On March 17, 2026, ConnectWise disclosed a critical vulnerability in ScreenConnect affecting all versions prior to 26.1 that could let attackers extract or abuse ASP.NET machine keys, hijack session authentication, gain unauthorized access, and escalate privileges. The company urged on-premises customers to treat remediation as urgent and said it had no evidence of active exploitation of this specific CVE.
ConnectWise published a security bulletin for ScreenConnect 26.1 security hardening, addressing a critical flaw later tracked as CVE-2026-3564. The update introduced stronger machine key protections, including encrypted storage and improved key management, and cloud-hosted instances were already mitigated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcescworld.com
Open sourcecsirt.sk
Open sourcecyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceccb.belgium.be
Open sourceconnectwise.com
Open sourceconnectwise.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.