CVE-2026-3564: ConnectWise ScreenConnect
Critical severity, CVSS 9.0. EPSS: 0.3% chance of exploitation in the next 30 days.
A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenConnect host and guest client agents are not independently affected by this CVE.
Affected products
- ConnectWise ScreenConnect
Published 2026-03-17. Last modified 2026-07-09.