CVE-2026-3564Patch

MEDIUMCVSS 9.0 · CRITICAL

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenConnect host and guest client agents are not independently affected by this CVE.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 23 mentions across 7 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 13 signals
  • Technical details provided in 15 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 3d ago at 8 mentions (2026-03-20); latest day: 1
  • 23 total mentions across 7 days

Deep dive

Activity timeline23 mentions / 7d
02468Mentions · 2026-03-17: 4Mentions · 2026-03-18: 5Mentions · 2026-03-19: 3Mentions · 2026-03-20: 8Mentions · 2026-03-22: 1Mentions · 2026-03-23: 1Mentions · 2026-03-25: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-22: 1Patch / Workaround · 2026-03-18: 4Patch / Workaround · 2026-03-19: 3Patch / Workaround · 2026-03-20: 4Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-17: 3Technical Details · 2026-03-18: 5Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 4Technical Details · 2026-03-22: 1Technical Details · 2026-03-25: 103-1703-1803-1903-2003-2203-2303-25
Signal classification5 categories
Patch
1043.5%
Disclosure
730.4%
General
313.0%
Active Exploitation
28.7%
Disclure
14.3%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-03-174
Disclosure3General1
2026-03-185
Disclosure1Patch4
2026-03-193
Patch3
2026-03-208
Active Exploitation1Disclosure3General2Patch2
2026-03-221
Active Exploitation1
2026-03-231
Disclure1
2026-03-251
Patch1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    Patch

    A critical 9.0 CVSS vulnerability (CVE-2026-3564) in ConnectWise ScreenConnect exposes server cryptographic keys. On-premise users must update to 26.1 now. https://securityonline.info/leaving-doors-unlocked-critical-9-cvss-screenconnect-flaw-cve-2026-3564/ https://t.co/z6q9R3Uby1

    Post summary

    The advisory reports a critical CVSS 9.0 flaw in ConnectWise ScreenConnect that exposes server cryptographic keys and urges users to update to version 26.1 immediately.

    070122807
    10.7K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    ScreenConnectサーバの乗っ取りが可能な脆弱性が悪用されている。CVE-2026-3564は特定の構成下でASP​.NETのマシンキーを抽出可能で、それを用いてセッションを乗っ取り可能なもの。バージョン26.1で修正。 https://www.helpnetsecurity.com/2026/03/20/connectwise-screenconnect-cve-2026-3564/

    Post summary

    CVE-2026-3564 permits extraction of ASP.NET machine keys and session takeover on ScreenConnect servers, and it is being actively exploited; a fixed version (26.1) has been released.

    011411.1K
    7.3K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    General

    Unpatched ScreenConnect servers open to attack (CVE-2026-3564) https://www.helpnetsecurity.com/2026/03/20/connectwise-screenconnect-cve-2026-3564/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    Article alerts that unpatched ScreenConnect servers are vulnerable to CVE-2026-3564, but does not provide exploitation details, patches, or technical specifics.

    00002425
    193.8K followersView on X
  • iototsecnews@iototsecnews
    Patch

    ScreenConnect の脆弱性 CVE-2026-3564 が FIX:マシンキー抽出とセッション乗っ取りの恐れ https://iototsecnews.jp/2026/03/18/screenconnect-vulnerability-allows-hackers-to-extract-unique-machine-keys-and-hijack-sessions/ 訳者後書:この脆弱性 CVE-2026-3564 の原因は、本来であれば厳重に管理されるべき認証用のマシン・キーが、設定ファイル内に平文で保存されていたことにあります。認証の根幹を支えるデータが、読み取り可能な状態で配置されていたことで、特別な権限を持たない攻撃者であっても、情報の取得が容易に行える状況にありました。 その結果、認証トークンの偽造が可能となり、正規のユーザーを装う攻撃者に対して、システムへの侵入を許すリスクが生じています。データの保存方法や検証プロセスの不備が、システム全体の信頼性を損なう深刻な事態に直結しています。運用中の環境が、バージョン 26.1 以上に更新されていることを速やかに確認する必要があります。 #ConnectWise #CVE20263564 #ScreenConnect #Vulnerability

    Post summary

    The article explains that CVE‑2026‑3564 allows attackers to extract plaintext machine keys, forge auth tokens, and hijack sessions, and recommends upgrading to version 26.1 as the patch to mitigate the vulnerability.

    01000110
    481 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-3564 - Critical A condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in ... https://www.thehackerwire.com/vulnerability/CVE-2026-3564/ https://t.co/Ed7GnR4WX2

    Post summary

    The text announces the discovery of a critical vulnerability (CVE-2026-3564) in ScreenConnect, describing how access to server‑level cryptographic materials can lead to unauthorized privileged access, but does not provide exploit code, PoC, or patch information.

    0000195
    138 followersView on X
  • キタきつね@foxbook
    Disclure

    パッチ未適用のScreenConnectサーバーが攻撃に対して脆弱(CVE-2026-3564) Unpatched ScreenConnect servers open to attack (CVE-2026-3564) #HelpNetSecurity (Mar 20) https://www.helpnetsecurity.com/2026/03/20/connectwise-screenconnect-cve-2026-3564/

    Post summary

    The article warns that unpatched ScreenConnect servers are vulnerable to CVE-2026-3564, but provides no evidence of active exploitation or technical details.

    00000203
    4.8K followersView on X
  • デジセキュア@dejital_secure
    Disclosure

    ScreenConnectの暗号署名検証不備CVE-2026-3564(CVSS 9.0)でセッション乗っ取りが可能との記事です。オンプレミス環境ではv26.1への即時更新が実務上の課題となっています。 https://www.helpnetsecurity.com/2026/03/20/connectwise-screenconnect-cve-2026-3564/ #脆弱性管理

    Post summary

    The article announces a critical CVE (CVE‑2026‑3564) in ScreenConnect that permits session hijacking, highlights its CVSS score of 9.0, and notes that updating to v26.1 is the recommended mitigation despite operational challenges.

    0000044
    8 followersView on X
  • Poseidon@PoseidonTPA
    Disclosure

    Unpatched ScreenConnect servers open to attack (CVE-2026-3564) http://news.poseidon-us.com/TRbnkw #HelpNetSecurity #Cybersecurity https://t.co/3E0F8fnE2M

    Post summary

    The tweet alerts that ScreenConnect servers remain unpatched and are vulnerable to CVE‑2026‑3564, directing readers to a news article for details.

    0000043
    757 followersView on X
  • ScyScan@ScyScan
    General

    Unpatched #ScreenConnect #servers open to attack (#CVE-2026-3564) https://www.scyscan.com/news/unpatched-screenconnect-servers-open-to-attack-cve-2026-3564/

    Post summary

    The tweet alerts that unpatched ScreenConnect servers are vulnerable to CVE‑2026‑3564. It does not provide any proof of concept, exploit code, active exploitation evidence, patch information, or technical details.

    0000047
    59 followersView on X
  • Varo@varosecurity
    Active Exploitation

    Servidores ScreenConnect sin parchear = sesiones remotas secuestradas. CVE-2026-3564 abusa de machine keys de http://ASP.NET para forjar autenticación. Si lo hosteás vos mismo, actualizá ya. Los MSPs son blanco prioritario. https://www.helpnetsecurity.com/2026/03/20/connectwise-screen…

    Post summary

    CVE-2026-3564 is actively exploited to hijack ScreenConnect sessions by forging ASP.NET authentication; patch immediately.

    0000049
    535 followersView on X
  • Help Net Security@helpnetsecurity
    Disclosure

    Unpatched ScreenConnect servers open to attack (CVE-2026-3564) - https://www.helpnetsecurity.com/2026/03/20/connectwise-screenconnect-cve-2026-3564/ - @ConnectWise #MSP #RemoteManagement #Vulnerability #Cybersecurity #CybersecurityNews

    Post summary

    The tweet references an article announcing CVE‑2026‑3564 against ScreenConnect servers but does not provide any technical, exploit, or remediation details.

    00000307
    60.0K followersView on X
  • Shah Sheikh@shah_sheikh
    Patch

    Unpatched ScreenConnect servers open to attack (CVE-2026-3564): ConnectWise has patched a critical vulnerability (CVE-2026-3564) that could enable attackers to hijack ScreenConnect sessions by abusing http://ASP.NET machine keys to forge trusted… https://www.helpnetsecurity.com/2026/03/20/connectwise-screenconnect-cve-2026-3564/?utm_source=dlvr.it&utm_medium=twitter https://t.co/XavRC6SqPR

    Post summary

    ConnectWise has released a patch for CVE‑2026‑3564, a critical vulnerability that could allow session hijacking through ASP.NET machine key abuse. The alert emphasizes the importance of applying the fix to prevent potential exploitation.

    0000048
    2.2K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    ConnectWise releases update for CVSS 9.0 flaw. Patch without delay! Extensive information, including fix info, at SecAlerts: CVE-2026-3564, CVSS 9.0: https://secalerts.co/vulnerability/CVE-2026-3564 #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #secalerts #CVE20263564 #ConnectWise https://t.co/ZEiJwR5fHx

    Post summary

    The tweet announces a ConnectWise update for CVE-2026‑3564, a high‑severity flaw, and directs readers to a SecAlerts page for patch details.

    00000122
    805 followersView on X
  • Eyal Estrin ☁️@eyalestrin
    Patch

    ConnectWise patches new flaw allowing ScreenConnect hijacking (CVE-2026-3564) http://dlvr.it/TRb61F #patchmanagement

    Post summary

    ConnectWise has released a patch for CVE‑2026‑3564, addressing a ScreenConnect hijacking flaw; no exploit details or active attacks are mentioned.

    0000078
    2.0K followersView on X
  • SempreUpdate@SempreUpdate
    Patch

    ConnectWise ScreenConnect corrige falha crítica CVE-2026-3564 e alerta administradores https://sempreupdate.com.br/connectwise-screenconnect-falha-critica-cve-2026-3564/

    Post summary

    ConnectWise ScreenConnect has released a critical fix for CVE-2026-3564 and issued advisories to administrators. The article does not include exploit code, active exploitation reports, or technical vulnerability details.

    0000059
    4.7K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    ConnectWise patched a critical flaw (CVE-2026-3564) in ScreenConnect before version 26.1 allowing attackers to extract http://ASP.NET machine keys, enabling session hijacking and privilege escalation. #ScreenConnect #Cryptography #USA https://ift.tt/gJYz7AL

    Post summary

    ConnectWise has released a patch for CVE‑2026‑3564, a flaw in ScreenConnect that could allow attackers to steal ASP.NET machine keys, enabling session hijacking and privilege escalation.

    00000132
    3.7K followersView on X
  • RedLegg@RedLegg
    Patch

    Security Bulletin:  ScreenConnect (CVE-2026-3564, CVSS 9.0) allows auth bypass via forged tokens from compromised keys. Upgrade to 26.1 now. #ThreatIntel #RedLeggCTI https://hubs.li/Q047sjdy0

    Post summary

    The bulletin announces CVE-2026-3564, a high‑CVSS auth‑bypass vulnerability, and advises upgrading to version 26.1 to apply the fix.

    0000062
    2.2K followersView on X
  • SH TC@shtc_social
    Patch

    🚨 ConnectWise ScreenConnect Açığı: Makine Anahtarları Çalınabilir CVE-2026-3564, http://ASP.NET anahtarlarının çalınmasına ve yetkisiz erişime izin veriyor. 26.1 sürümüne yükseltin! #ConnectWise #CVE20263564 #SiberGüvenlik 🔗 https://sh.tc/connectwise-screenconnect-acigi-cve-2026-3564-makine-anahtarlari-calinebilir-363

    Post summary

    The post announces CVE-2026-3564, notes it allows ASP.NET key theft and unauthorized access, and urges users to upgrade to version 26.1 to mitigate.

    0000051
    110 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Improper Verification of Cryptographic Signature vulnerability in #ScreenConnect. CVE-2026-3564 CVSS: 9.0. Unauthenticated attackers can get access to machine keys and use them to elevate their access. #Patch #Patch #Patch

    Post summary

    The tweet alerts to a high‑severity vulnerability (CVE‑2026‑3564) in ScreenConnect that allows unauthenticated attackers to access machine keys and elevate privileges, but it offers no exploit code, patch details, or evidence of active exploitation.

    00000220
    7.2K followersView on X
  • ThreatCluster@threatcluster
    Patch

    ConnectWise ScreenConnect flaw CVE-2026-3564 allows unauthenticated access and session hijack. All versions before 26.1 affected. Patch immediately and apply 26.1 hardening. #Vulnerability https://threatcluster.io/cluster/critical-vulnerability-in-connectwise-screenconnect-exposes--16776372

    Post summary

    The tweet announces CVE-2026-3564 in ConnectWise ScreenConnect, emphasizes that all versions before 26.1 are vulnerable, and urges users to patch immediately.

    0000055
    104 followersView on X

Explore more