ScreenConnect Vulnerability Exposes Machine Keys, Enables Session Hijacking

Related

Hackers Exploit Critical Auth Bypass in Gitea Docker Image

What happened Hackers are actively exploiting a critical authentication bypass...

Zimbra Urges Customers to Patch Critical Web Client XSS Flaw

What happened Zimbra urged customers to patch a critical stored...

Progress Urges ShareFile Customers to Shut Down Servers Over Credible Threat

What happened Progress Software warned ShareFile customers using Storage Zone...

Ubiquiti Discloses 25 Security Flaws Across UniFi Ecosystem

What happened Ubiquiti disclosed 25 security vulnerabilities affecting products across...

AirDrop and Quick Share Flaws Allow Attackers to Crash Nearby Devices

What happened Security researchers disclosed multiple vulnerabilities affecting Apple AirDrop...

Share

What happened

ConnectWise disclosed a critical vulnerability in its ScreenConnect remote access software that allows attackers to extract unique machine keys and hijack active sessions. The flaw stems from how earlier versions stored cryptographic machine keys in server configuration files, which under certain conditions could be accessed by unauthorized actors. If extracted, these keys can be used to impersonate legitimate sessions and bypass authentication controls. The vulnerability, tracked as CVE-2026-3564, carries a CVSS score of 9.0, indicating critical severity. Researchers noted that once the keys are compromised, attackers can gain persistent access and potentially take full control of affected systems without requiring user interaction. 

Who is affected

Organizations using on-premises versions of ConnectWise ScreenConnect, particularly older or unpatched deployments, are affected, as attackers can exploit exposed machine keys to hijack sessions and access managed systems. 

Why CISOs should care

The vulnerability impacts a remote access platform with administrative-level control over endpoints, meaning successful exploitation can lead to widespread compromise across managed environments. 

3 practical actions

  1. Upgrade ScreenConnect immediately. Apply updates that secure machine key handling and prevent unauthorized extraction. 
  2. Audit server configuration exposure. Ensure sensitive cryptographic material is not accessible or improperly stored. 
  3. Monitor for session anomalies. Detect unauthorized session activity that may indicate key misuse or impersonation. 

For more coverage of newly disclosed security flaws and active exploitation, explore our reporting under the Vulnerabilities tag.

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.