ConnectWise fixes ScreenConnect vulnerability; unauthorized access possible.
Mar 18, 2026 // 21:58 - Norina Velotta


ConnectWise is alerting ScreenConnect users to a flaw in how cryptographic signatures are checked. This weakness could allow unauthorized individuals to gain access and increase their privileges.

The issue affects ScreenConnect versions older than 26.1 and is identified as CVE-2026-3564, receiving a critical risk rating.

ScreenConnect is a platform for remote access typically used by managed service providers (MSPs), IT departments, and support teams. It can be hosted in the cloud by ConnectWise or installed on the customer’s own server.

A malicious actor could take advantage of this vulnerability to obtain and utilize the ASP.NET machine keys for improper session validation.

“If the machine key information for a ScreenConnect installation is exposed, an attacker might be able to create or alter secure data in ways that the installation accepts as legitimate,” the vendor’s notice states.

“This could lead to unauthorized entry and actions within ScreenConnect.”

The vendor has resolved this issue by providing stronger protection for machine keys, like encrypted storage and better handling, starting with ScreenConnect version 26.1.

Cloud users have automatically been updated to the secure version, but system administrators responsible for on-premises deployments are urged to upgrade to version 26.1 promptly.

ConnectWise also mentioned that security researchers have seen attempts to misuse revealed ASP.NET machine key data in live scenarios, making the threat from CVE-2026-3564 an immediate concern.

However, the company informed BleepingComputer that they do not currently have evidence of active exploitation, and thus have no indicators of compromise (IoCs) to provide.

“We have no evidence that this specific vulnerability (CVE-2026-3564) was exploited in ConnectWise-hosted ScreenConnect, so we don’t have verified indicators of compromise to share,” ConnectWise told BleepingComputer.

“We encourage any researchers who believe they have identified active exploitation to engage in responsible disclosure so findings can be validated and addressed appropriately.”

However, there are reports that Chinese attackers have been exploiting the issue for years; however, it’s not clear if the same vulnerability was used.

Previously, attacks by nation-state hackers exploited CVE-2025-3935 to steal the secret machine keys used by ScreenConnect servers.

Besides upgrading to ScreenConnect version 26.1, the software vendor also advises strengthening access controls to configuration files and sensitive information, monitoring logs for unusual authentication activity, securing backups and old data snapshots, and keeping extensions updated.

#access  #connectwise  #fixes  #news  #possible  #screenconnect  #unauthorized  #vulnerability   —   News