• News/
  • https://www.bleepingcomputer.com/news/security/connectwise-patches-new-flaw-allowing-screenconnect-hijacking/

ConnectWise patches new flaw allowing ScreenConnect hijacking

BleepingComputer
·
Bill Toulas
·
Published Mar 18, 2026
·
Updated

ConnectWise is warning ScreenConnect customers of a cryptographic signature verification vulnerability that could lead to unauthorized access and privilege escalation. The flaw affects ScreenConnect versions before 26.1. It is tracked as CVE-2026-3564 and received a critical severity score. ScreenConnect is a remote access platform typically used by managed service providers (MSPs), IT departments, and support teams. It can be either cloud-hosted by ConnectWise or on-premise on the customer's server. An attacker could exploit the security issue to extract and use the ASP.NET machine keys for unauthorized session authentication. “If the machine key material for a ScreenConnect instance is disclosed, a threat actor may be able to generate or modify protected values in ways that may be accepted by the instance as valid,” reads the vendor’s advisory. “This can result in unauthorized access and unauthorized actions within ScreenConnect.” The vendor addressed this by adding stronger protection for machine keys, including encrypted storage and improved handling starting ScreenConnect version 26.1. Cloud users have been automatically moved to the safe version, but system administrators managing on-premises deployments must upgrade to version 26.1 as soon as possible. ConnectWise also stated that researchers observed attempts to abuse disclosed ASP.NET machine key material in the wild, so the risk from CVE-2026-3564 is tangible right now. However, the vendor told BleepingComputer tha...

Read full article

Affected Software

1 affected component
ConnectWise ScreenConnect<26.1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly patched vulnerability in ConnectWise ScreenConnect that could allow screen hijacking.

2

What security implications are discussed?

The vulnerability could lead to unauthorized access and privilege escalation on affected systems.

3

What versions of ScreenConnect are affected by this vulnerability?

The flaw affects all versions of ScreenConnect prior to version 26.1.

4

What company is responsible for the ScreenConnect software?

ConnectWise is the company responsible for the ScreenConnect software.

5

What action should users of ScreenConnect take in response to the article?

Users of ScreenConnect should update to version 26.1 or later to mitigate the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203