PT-2026-25901 · Connectwise · Screenconnect

Published

2026-03-17

·

Updated

2026-03-20

·

CVE-2026-3564

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ScreenConnect versions prior to 26.1
Description A flaw in ScreenConnect could allow an attacker with access to server-level cryptographic material used for authentication to gain unauthorized access, potentially including elevated privileges. This is due to an improper verification of cryptographic signatures, where earlier versions stored unique machine keys per instance within server configuration files. Exploitation requires prior access to the server-level cryptographic material. The vulnerability is considered critical and has a CVSS score of 9.0. The issue could allow attackers to forge authenticated sessions and escalate privileges within a ScreenConnect instance, potentially impacting downstream client environments, especially given ScreenConnect's use by Managed Service Providers. The machine key attack surface is of particular concern, as publicly exposed machine keys have been observed being misused to inject malicious code into servers.
Recommendations Upgrade to ScreenConnect version 26.1.

Fix

LPE

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2026-3564

Affected Products

Screenconnect