ConnectWise ScreenConnect cryptographic signature bypass leading to unauthorized access fixed in version 26.1
Updated:
· First: 18.03.2026 20:10
· 📰 1 src / 1 articles
A critical cryptographic signature verification vulnerability in ConnectWise ScreenConnect versions prior to 26.1 allows attackers to extract ASP.NET machine keys and forge authentication tokens, enabling unauthorized access and privilege escalation. The flaw, tracked as CVE-2026-3564, affects both cloud-hosted and on-premises deployments and has been observed being targeted in the wild. Exploitation results in unauthorized session authentication and potential compromise of managed systems accessed via ScreenConnect.