Find notable cyber news and cases, enriched with sources, timelines, and signals.
Exploitation Wave Security Patch Release Vulnerability

Sitecore ViewState exploitation and ScreenConnect machine-key hardening

Updated 18.03.2026 20:10
Case score 57
Case score 57 Members 3 Latest activity 18.03.2026 20:10
Active exploitation Patch available CVSS: 9.0 Critical
Members 3 First seen 05.09.2025 01:05 Last seen 18.03.2026 20:10 Updated 18.03.2026 20:10

Overview

Attackers are exploiting **Sitecore CVE-2025-53690** by abusing exposed **ASP.NET machine keys** to get remote code execution on internet-facing deployments. Mandiant reported follow-on use of **WEEPSTEEL**, privilege escalation, persistence, reconnaissance, and lateral movement, and CISA told **FCEB agencies** to update Sitecore by **September 25, 2025**. ConnectWise later disclosed **CVE-2026-3564** in **ScreenConnect**, another machine-key handling flaw that can enable unauthorized authentication and privilege escalation, and shipped **ScreenConnect 26.1** with stronger key protection. Available evidence does not show active exploitation of that ScreenConnect flaw, and the number of affected Sitecore organizations remains unquantified.

Signals

8 derived
Exploitation
Exploitation Active exploitation CVSS 9.0 Critical
CVEs/products
CVE CVE
Remediation
Urgency High Remediation Patch available
Threat context
Tooling Malware

Malware context

1 families · 6 tools
Tools
ScreenConnect DWAgent EarthWorm Godzilla GoTokenTheft SharpHound

Member happenings

3 related
Exploitation Wave ViewState deserialization attack wave (2025)
Updated 05.09.2025 01:05 Lead Contribution 57
Exploitation Active Exploitation CVSS 9.0 Critical

A **2025 ViewState deserialization attack wave** is continuing to expose **ASP.NET** deployments to **remote code execution** when machine keys are leaked or improperly protected. The latest case is **CVE-2025-53690** in **Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud**, where attackers abused an exposed **ASP.NET machine key** to compromise internet-facing servers. **CISA** has told **FCEB agencies** to update Sitecore by **September 25, 2025** as **Mandiant** reported active exploitation, deployment of **WEEPSTEEL**, and follow-on use of tools such as **EarthWorm** and **SharpHound** for reconnaissance, persistence, lateral movement, and **data theft**.

Security Patch Release ConnectWise security patch release for CVE-2026-3564
Updated 18.03.2026 20:10 Context
Urgency High Patch Patch Available

ConnectWise released **ScreenConnect 26.1** to harden **machine key** handling after disclosing **CVE-2026-3564**, a flaw that can enable **unauthorized access** and **privilege escalation**. The update covers **ScreenConnect versions before 26.1** and adds **encrypted storage** plus improved handling for machine keys. **Cloud** customers were moved to the safe version automatically, while **on-premises** administrators were told to upgrade **as soon as possible**. ConnectWise also said it has **no evidence of active exploitation** in its hosted service, even though attempts to abuse disclosed machine key material were observed in the wild.

Vulnerability ScreenConnect cryptographic signature verification vulnerability (CVE-2026-3564)
Updated 18.03.2026 20:10 Context
Exploitation No Known Exploitation Patch Patch Available

ConnectWise disclosed **CVE-2026-3564**, a **cryptographic signature verification vulnerability** in **ScreenConnect** that can enable **unauthorized access** and **privilege escalation**. The flaw affects **versions before 26.1** and may let an attacker abuse **ASP.NET machine keys** for **unauthorized session authentication**. **ScreenConnect 26.1** adds stronger machine-key protection, and **on-premises** administrators are being told to upgrade as soon as possible. ConnectWise said it has **no evidence of active exploitation** of this specific flaw and **no confirmed IOCs** to share.