ConnectWise is warning ScreenConnect customers of a cryptographic signature verification vulnerability that could lead to unauthorized access and privilege escalation. The flaw affects ScreenConnect versions before 26.1. It is tracked as CVE-2026-3564 and received a critical severity score. ScreenConnect is a remote access platform typically used by managed service providers (MSPs), IT departments, and support teams. It can be either cloud-hosted by ConnectWise or on-premise on the customer's server. An attacker could exploit the security issue to extract and use the ASP.NET machine keys for unauthorized session authentication. “If the machine key material for a ScreenConnect instance is disclosed, a threat actor may be able to generate or modify protected values in ways that may be accepted by the instance as valid,” reads the vendor’s advisory. “This can result in unauthorized access and unauthorized actions within ScreenConnect.” The vendor addressed this by adding stronger protection for machine keys, including encrypted storage and improved handling starting ScreenConnect version 26.1. Cloud users have been automatically moved to the safe version, but system administrators managing on-premises deployments must upgrade to version 26.1 as soon as possible. ConnectWise also stated that researchers observed attempts to abuse disclosed ASP.NET machine key material in the wild, so the risk from CVE-2026-3564 is tangible right now. However, the vendor told BleepingComputer tha...
ConnectWise patches new flaw allowing ScreenConnect hijacking
BleepingComputer
·Bill Toulas
·Published Mar 18, 2026
·Updated
Affected Software
1 affected component
ConnectWise ScreenConnect<26.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a newly patched vulnerability in ConnectWise ScreenConnect that could allow screen hijacking.
2
What security implications are discussed?
The vulnerability could lead to unauthorized access and privilege escalation on affected systems.
3
What versions of ScreenConnect are affected by this vulnerability?
The flaw affects all versions of ScreenConnect prior to version 26.1.
4
What company is responsible for the ScreenConnect software?
ConnectWise is the company responsible for the ScreenConnect software.
5
What action should users of ScreenConnect take in response to the article?
Users of ScreenConnect should update to version 26.1 or later to mitigate the vulnerability.