ScreenConnect Flaw Lets Hackers Steal Machine Keys and Hijack Sessions
ConnectWise has released a critical security update for its ScreenConnect remote desktop software to address a severe vulnerability that allows attackers to hijack user sessions. The flaw, which compromises the protection of server-level cryptographic…
ConnectWise has released a critical security update for its ScreenConnect remote desktop software to address a severe vulnerability that allows attackers to hijack user sessions. The flaw, which compromises the protection of server-level cryptographic material, prompted the company to issue a Priority 1 security bulletin, warning users of a high risk of active exploitation.
Tracked under CVE-2026-3564, the vulnerability stems from improper verification of cryptographic signatures within the software architecture and is officially categorized as CWE-347. Older versions of ConnectWise ScreenConnect stored unique machine keys per instance directly within server configuration files. Under specific network conditions, an unauthorized threat actor who compromises server integrity can extract this sensitive cryptographic material.
Once attackers possess the machine keys, they can misuse them to forge session authentication. This allows unauthorized access to connected endpoints and compromises confidential data. The security flaw carries a critical CVSS v3.1 base score of 9.0 out of 10, reflecting severe confidentiality, integrity, and availability impacts on compromised systems despite the high attack complexity. All deployments of ScreenConnect before version 26.1 are vulnerable to this exploit.
Older versions of ConnectWise ScreenConnect stored unique machine keys per instance directly within server configuration files.
To mitigate this threat, ConnectWise released ScreenConnect version 26.1, which introduces significant security hardening measures for authentication processes. The update overhauls the handling of machine keys, replacing localized configuration file storage with encrypted storage and active key management, drastically reducing the risk of unauthorized access.
ConnectWise classifies this flaw as a Priority 1 threat, indicating that organizations should treat this patch as an emergency change. For cloud-hosted ScreenConnect instances, ConnectWise has already applied the necessary patches on the backend infrastructure. No further action is required for cloud customers to remain protected against this vulnerability.
On-premise administrators must take immediate manual action to secure their environments. Organizations running local deployments need to download and install ScreenConnect version 26.1 directly from the ConnectWise portal. Administrators with expired maintenance licenses must renew their licenses before applying this update. Partners using on-premises ScreenConnect installations integrated with ConnectWise Automate can acquire the 26.1 update through the standard Automate Product Updates page.
Based on reporting by GBHackers.
