>> All posts

CVE-2026-3564: ConnectWise ScreenConnect privilege escalation via server cryptographic material

The short version: ConnectWise ScreenConnect has a privilege-escalation flaw (CVE-2026-3564): an actor who already possesses the server's authentication cryptographic material can, in certain scenarios, obtain unauthorized and elevated access. ConnectWise rates it 9.0, but the precondition is steep, there's no known exploitation, and it isn't in CISA's KEV catalog. Patch it on your normal cycle and rotate the material. Steady hands, no alarm.

At a glance

FactDetail
Our severity takeModerate — in practice (see below)
CVSS v3.1 (NVD)Unknown at time of writing — NVD record awaiting enrichment
CVSS (ConnectWise, CNA)9.0 — Critical · AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS0.36% · 28.48th percentile (2026-07-17)
In CISA KEV?No
Known exploited?Not at time of writing
Vulnerability typeCWE-347 improper verification of cryptographic signature → privilege escalation
Requires authenticated session?Effectively yes — the attacker must already hold the server's authentication cryptographic material
AffectedScreenConnect server versions prior to 26.1
Fixed inScreenConnect 26.1

What you need to know

The flaw is a signature-verification weakness: in certain scenarios an actor with the server's authentication cryptographic material can obtain access they shouldn't, including elevated privileges.

  • The precondition does the gating. The attacker must already possess server-level cryptographic material used for authentication. That's not something an external, unauthenticated attacker has — it implies prior compromise or insider access.
  • The paper score is high, the practical urgency is lower. ConnectWise's 9.0 reflects worst-case impact if that precondition is met; NVD hasn't scored it yet. Attack complexity is High even in the vendor's own vector.
  • No exploitation reported. EPSS is low and it isn't in KEV — a real issue to fix, not a fire drill.

How serious we see it

Moderate — on-paper Critical, practically a step below.

We rate by real-world exposure, and this one's danger is bounded by a demanding prerequisite: possession of the server's cryptographic material. Absent prior compromise, an outside attacker can't reach it. With no known exploitation and no KEV listing, this belongs on a normal patch cycle rather than an emergency one — while still being worth closing, because the impact if the precondition is met is elevated access. The reassuring part is clarity: a specific version boundary and a published fix.

Two notes for accuracy: NVD has not yet published its own analysis (the CVSS above is ConnectWise's), and if new exploitation emerges, we'll revise this take upward.

Recommendations

Straight from ConnectWise's advisory:

  1. Patch on your normal cycle. Upgrade ScreenConnect to 26.1 or later.
  2. Rotate server cryptographic material if you have any suspicion of prior compromise — that material is the enabling condition here.
  3. Tighten server access. Restrict and monitor who can reach server-level secrets and the ScreenConnect host.
  4. Watch for status changes. If this moves into KEV or exploitation is reported, prioritize accordingly.
  5. Confirm your exposure first. Verify whether you run a self-hosted ScreenConnect and which version.

How BreachRisk sees it

BreachRisk discovers internet-facing ScreenConnect from little more than your domain and fingerprints the version, so an affected server surfaces in your external footprint. We identify and flag the exposed version; we don't exploit it. For a flaw like this — high on paper but gated by a steep precondition and not yet exploited — that context is the point: you see it ranked honestly, addressed on cadence rather than mistaken for a live emergency.

References

See your cyber risk, proven.