kokumօtօ[verified]@__kokumotoActive Exploitation
CVE-2026-3564 permits extraction of ASP.NET machine keys and session takeover on ScreenConnect servers, and it is being actively exploited; a fixed version (26.1) has been released.
The Cyber Security Hub™[verified]@TheCyberSecHubGeneral
Article alerts that unpatched ScreenConnect servers are vulnerable to CVE-2026-3564, but does not provide exploitation details, patches, or technical specifics.
キタきつね[verified]@foxbookDisclure
The article warns that unpatched ScreenConnect servers are vulnerable to CVE-2026-3564, but provides no evidence of active exploitation or technical details.
Shah Sheikh[verified]@shah_sheikhPatch
ConnectWise has released a patch for CVE‑2026‑3564, a critical vulnerability that could allow session hijacking through ASP.NET machine key abuse. The alert emphasizes the importance of applying the fix to prevent potential exploitation.
SH TC[verified]@shtc_socialPatch
The post announces CVE-2026-3564, notes it allows ASP.NET key theft and unauthorized access, and urges users to upgrade to version 26.1 to mitigate.
ThreatCluster[verified]@threatclusterPatch
The tweet announces CVE-2026-3564 in ConnectWise ScreenConnect, emphasizes that all versions before 26.1 are vulnerable, and urges users to patch immediately.
Gray Hats@the_yellow_fallPatch
The advisory reports a critical CVSS 9.0 flaw in ConnectWise ScreenConnect that exposes server cryptographic keys and urges users to update to version 26.1 immediately.
iototsecnews@iototsecnewsPatch
The article explains that CVE‑2026‑3564 allows attackers to extract plaintext machine keys, forge auth tokens, and hijack sessions, and recommends upgrading to version 26.1 as the patch to mitigate the vulnerability.