Back

CRITICAL

ScreenConnect Instance Level Cryptographic Material Exposure

Published Mar 17, 2026

Description

A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenConnect host and guest client agents are not independently affected by this CVE.

Affected products

Remediation

Vendor solution

Cloud: No action is required. ScreenConnect servers hosted in “screenconnect.com” cloud (standalone and Automate/RMM integrated) or “hostedrmm.com” for Automate partners have been updated to remediate the issue.  

On-premise ScreenConnect Partners:

Please upgrade to ScreenConnect Server version 26.1. Visit Download | ScreenConnect page to download and apply the update (access requires a valid on-premises license). 

* If your license is out of maintenance, you must upgrade your license https://docs.connectwise.com/ScreenConnect_Documentation/On-premises/On-premises_licensing/Renew_or_upgrade_an_on-premises_license  before installing the latest supported release of ScreenConnect. * For instructions on updating to the newest release, please reference this doc: Upgrade an on-premise installation - ConnectWise 

Automate On-Prem Partners with ScreenConnect Integration:

For partners using an on-premises ScreenConnect installation integrated with Automate, ScreenConnect 26.1 is available through the Automate Product Updates https://docs.connectwise.com/ConnectWise_Automate_Documentation/Automate_Product_Updates page.

Link to release notes: ScreenConnect 26.1 / ScreenConnect https://screenconnect.product.connectwise.com/communities/26/topics/5088-screenconnect-261

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ConnectWise
Published Mar 17, 2026
Updated Jul 9, 2026
Reserved Mar 4, 2026

CISA Vulnrichment

Updated Mar 17, 2026

NVD

Status Awaiting Analysis
Modified Jul 9, 2026

Red Hat

No data

ENISA EUVD

Assigner ConnectWise
Published Mar 17, 2026
Updated Jul 9, 2026

GitHub

No data