{"id":"CVE-2026-3564","title":"A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios","summary":"A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenCon…","severity":"critical","cvss":9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-347"],"published":"2026-03-17","updated":"2026-07-09","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-3564","references":[{"url":"https://www.connectwise.com/company/trust/security-bulletins/2026-03-17-screenconnect-bulletin","label":"7d616e1a-3288-43b1-a0dd-0a65d3e70a49"}],"tags":["nvd"],"epss":0.00362,"epssPercentile":0.29935,"ingestedAt":"2026-07-10T01:55:22.961Z","slug":"CVE-2026-3564","body":"## Overview\n\nA condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenConnect host and guest client agents are not independently affected by this CVE.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":49.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}