ScreenConnect Vulnerability Allows Hackers to Extract Unique Machine Keys and Hijack Sessions
## ScreenConnect Security Vulnerability Advisory
ScreenConnect Security Vulnerability Advisory
ConnectWise has released a security advisory concerning its ScreenConnect remote desktop software. A critical cryptographic vulnerability, identified as CVE-2026-3564, could allow unauthorized attackers to extract server-level machine keys and hijack session authentication.
The vulnerability affects all ScreenConnect versions prior to 26.1 and has been assigned a CVSS score of 9.0, indicating a critical severity level. The issue arises from the storage of machine keys and cryptographic identifiers in plaintext within server configuration files. This flaw enables attackers with filesystem access to extract the keys without elevated privileges.
Extracted machine keys could be used to manipulate session authentication tokens, allowing attackers to impersonate legitimate sessions and bypass access controls. The vulnerability is classified under CWE-347, highlighting improper verification of cryptographic signatures. The CVSS vector indicates network exploitability without privileges or user interaction, though specific conditions must be met.
The scope is marked as Changed, meaning an exploit could impact resources beyond the affected component, posing a significant risk in enterprise environments where ScreenConnect is widely used.
ConnectWise has released a security advisory concerning its ScreenConnect remote desktop software.
ConnectWise has categorized this vulnerability as Priority 1 (High), urging immediate action. Organizations using on-premises ScreenConnect deployments should prioritize updating to version 26.1, which introduces encrypted storage and enhanced key management. This update mitigates the risk of unauthorized key extraction even if server integrity is compromised.
Cloud-hosted ScreenConnect instances have already been updated by ConnectWise, requiring no further action. On-premises users must manually upgrade through the official ScreenConnect download page. It is important to note that lapsed maintenance licenses must be renewed to apply the update.
Security teams should immediately patch and audit session logs for any unusual authentication activity that could indicate attempted exploitation.
Based on reporting by Cyber Security News.
