ConnectWise has issued an urgent security warning regarding a critical vulnerability in its remote access tool ScreenConnect. The flaw, identified as CVE-2026-3564, impacts all versions prior to 26.1 and carries a high severity rating due to its potential consequences.ScreenConnect is widely used by managed service providers (MSPs), IT teams, and support organizations for remote system management. It can be deployed either through cloud hosting by ConnectWise or installed on-premises by customers. The vulnerability specifically involves improper handling of cryptographic signature verification, which could allow attackers to extract sensitive ASP.NET machine keys. If these machine keys are exposed, a malicious actor could forge or tamper with authentication data that the system would incorrectly treat as legitimate. This opens the door to unauthorized session creation, privilege escalation, and the execution of actions within the compromised environment without proper authorization. Essentially, attackers could gain control over systems managed through ScreenConnect.To address the issue, ConnectWise introduced stronger safeguards in version 26.1, including encrypting machine key storage and improving how these keys are managed. Cloud-hosted users have already been migrated to the secure version, but organizations running on-premises instances must update immediately to mitigate risk. Although there is currently no confirmed evidence of exploitation specifically tied to CVE-2026-3564, security researchers have observed attempts to abuse exposed machine key material in real-world scenarios. Additionally, past incidents involving CVE-2025-3935 demonstrated how attackers, including suspected nation-state groups, could steal machine keys for malicious purposes.ConnectWise advises administrators to upgrade promptly, restrict access to configuration files, monitor authentication logs for suspicious activity, secure backups, and ensure all extensions remain updated.
Authorities recently dismantled a massive IoT-based botnet responsible for launching record-breaking distributed denial-of-service (DDoS) attacks reaching up to 30 Tbps. The operat...
Cisco firewall appliances are actively being targeted through critical zero-day vulnerabilities that enable unauthenticated attackers to gain full control over affected systems. Th...
The ransomware group LeakNet is expanding operations by developing its own infection and execution infrastructure, reducing reliance on initial access brokers. key innovation in it...