Cybersecuritynews Critical Vulnerability in ConnectWise ScreenConnect Allows Unauthorized Access
Article Content
- •CVE-2026-3564 allows unauthorized access via cryptographic signature verification flaws.
- •ConnectWise ScreenConnect versions prior to 26.1 are affected and need immediate patching.
- •No confirmed active exploitation has been reported, but the risk remains high.
ConnectWise has released a patch for its ScreenConnect remote support tool to address a critical vulnerability, tracked as CVE-2026-3564, that could allow unauthorized access and privilege escalation. This flaw affects all versions prior to 26.1 and involves the extraction of server-level cryptographic material used for session authentication. Attackers could exploit this vulnerability to hijack sessions and perform unauthorized actions. The National Institute of Standards and Technology (NIST) has classified this vulnerability as critical, indicating a high risk of exploitation in the wild. ConnectWise has urged its customers, particularly managed service providers (MSPs), to upgrade to version 26.1 immediately. While there are claims of past exploitation by state-sponsored actors, ConnectWise currently has no evidence of active exploitation of this specific vulnerability. MSPs managing on-premises deployments must take prompt action to secure their systems. The vulnerability was publicly disclosed on March 17, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track ConnectWise and CVE-2025-3935 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…