CVE-2026-3564

CRITICAL EXPLOITED

ScreenConnect Instance Level Cryptographic Material Exposure

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-3564 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenConnect host and guest client agents are not independently affected by this CVE.

Scores

CVSS v3 9.0
EPSS 0.0036
EPSS Percentile 28.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2026-03-17
CWE
CWE-347
Status published
Products (2)
ConnectWise/ScreenConnect All server versions prior to 26.1
ConnectWise/ScreenConnect All versions prior to 26.1
Published Mar 17, 2026
Tracked Since Mar 17, 2026