Unrated severityNVD Advisory· Published Mar 17, 2026· Updated Mar 18, 2026
ScreenConnect Instance Level Cryptographic Material Exposure
CVE-2026-3564
Description
A condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios.
Affected products
1- Range: All versions prior to 26.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
6- CloudZ RAT potentially steals OTP messages using Pheno pluginCisco Talos Intelligence · May 5, 2026
- Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM ToolsThe Hacker News · May 4, 2026
- TeamPCP Weekly Analysis: 2026-W18 (2026-04-27 through 2026-05-03), (Mon, May 4th)SANS Internet Storm Center · May 4, 2026
- CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEVThe Hacker News · Apr 29, 2026
- 23rd March – Threat Intelligence ReportCheck Point Research · Mar 23, 2026
- CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA Alerts