Find notable cyber news and cases, enriched with sources, timelines, and signals.
Exploitation Wave Security Patch Release Vulnerability

Sitecore ViewState exploitation and ScreenConnect machine-key hardening

Updated 18.03.2026 20:10
Case score 57
Members 3 First seen 05.09.2025 01:05 Latest activity 18.03.2026 20:10

Overview

Attackers are exploiting **Sitecore CVE-2025-53690** by abusing exposed **ASP.NET machine keys** to get remote code execution on internet-facing deployments. Mandiant reported follow-on use of **WEEPSTEEL**, privilege escalation, persistence, reconnaissance, and lateral movement, and CISA told **FCEB agencies** to update Sitecore by **September 25, 2025**. ConnectWise later disclosed **CVE-2026-3564** in **ScreenConnect**, another machine-key handling flaw that can enable unauthorized authentication and privilege escalation, and shipped **ScreenConnect 26.1** with stronger key protection. Available evidence does not show active exploitation of that ScreenConnect flaw, and the number of affected Sitecore organizations remains unquantified.
Latest development Open development history 4 earlier developments ScreenConnect 26.1 hardens machine-key handling ConnectWise says ScreenConnect 26.1 strengthens machine-key protection with encrypted storage and improved handling, with cloud users moved to the safe version automatically and on-premises administrators told to upgrade as soon as possible.
  1. Earlier development

    ConnectWise warns of ScreenConnect CVE-2026-3564

    ConnectWise warns ScreenConnect customers about CVE-2026-3564, a critical cryptographic signature verification flaw affecting ScreenConnect versions before 26.1 that could let an attacker abuse ASP.NET machine keys for unauthorized session authentication, leading to unauthorized access and privilege escalation.

  2. Earlier development

    ConnectWise warns ScreenConnect customers about CVE-2026-3564

    ConnectWise warned ScreenConnect customers about CVE-2026-3564, a cryptographic signature verification vulnerability affecting ScreenConnect versions before 26.1 that could let an attacker abuse ASP.NET machine keys for unauthorized session authentication, unauthorized access, and privilege escalation. The vendor said researchers observed attempts to abuse disclosed ASP.NET machine key material in the wild, but it had no evidence of active exploitation in ConnectWise-hosted ScreenConnect and no confirmed IOCs to share. ScreenConnect 26.1 adds stronger machine-key protection, and on-premises administrators are told to upgrade as soon as possible while also tightening access to configuration files and secrets, checking logs for unusual authentication activity, protecting backups and old data snapshots, and keeping extensions up to date.

  3. Earlier development

    Sitecore zero-day CVE-2025-53690 is exploited through exposed ASP.NET machine keys

    A critical Sitecore zero-day tracked as CVE-2025-53690 was under active ViewState deserialization exploitation against Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce deployments, with attackers leveraging an exposed ASP.NET machine key from Sitecore deployment guides from 2017 and earlier to achieve remote code execution.

  4. Earlier development

    Mandiant disrupts an active ViewState deserialization attack on a Sitecore server

    Mandiant Threat Defense said it discovered an active ViewState deserialization attack affecting Sitecore deployments that leveraged a sample machine key exposed in Sitecore deployment guides from 2017 and earlier, then initiated rapid response and successfully disrupted the attack on a Sitecore server before the full attack cycle could be observed.

Signals

Impact signals
Exploitation
CVEs/products
Remediation
Threat context

Threat actor context

1 listed

Malware & tooling context

1 families · 6 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Exploitation Wave ViewState deserialization attack wave (2025)
Updated 05.09.2025 01:05 Lead Contribution 57
Exploitation Active Exploitation CVSS 9.0 Critical

A **2025 ViewState deserialization attack wave** is continuing to expose **ASP.NET** deployments to **remote code execution** when machine keys are leaked or improperly protected. The latest case is **CVE-2025-53690** in **Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud**, where attackers abused an exposed **ASP.NET machine key** to compromise internet-facing servers. **CISA** has told **FCEB agencies** to update Sitecore by **September 25, 2025** as **Mandiant** reported active exploitation, deployment of **WEEPSTEEL**, and follow-on use of tools such as **EarthWorm** and **SharpHound** for reconnaissance, persistence, lateral movement, and **data theft**.

Security Patch Release ConnectWise security patch release for CVE-2026-3564
Updated 18.03.2026 20:10 Context
Urgency High Patch Patch Available

ConnectWise released **ScreenConnect 26.1** to harden **machine key** handling after disclosing **CVE-2026-3564**, a flaw that can enable **unauthorized access** and **privilege escalation**. The update covers **ScreenConnect versions before 26.1** and adds **encrypted storage** plus improved handling for machine keys. **Cloud** customers were moved to the safe version automatically, while **on-premises** administrators were told to upgrade **as soon as possible**. ConnectWise also said it has **no evidence of active exploitation** in its hosted service, even though attempts to abuse disclosed machine key material were observed in the wild.

Vulnerability ScreenConnect cryptographic signature verification vulnerability (CVE-2026-3564)
Updated 18.03.2026 20:10 Context
Exploitation No Known Exploitation Patch Patch Available

ConnectWise disclosed **CVE-2026-3564**, a **cryptographic signature verification vulnerability** in **ScreenConnect** that can enable **unauthorized access** and **privilege escalation**. The flaw affects **versions before 26.1** and may let an attacker abuse **ASP.NET machine keys** for **unauthorized session authentication**. **ScreenConnect 26.1** adds stronger machine-key protection, and **on-premises** administrators are being told to upgrade as soon as possible. ConnectWise said it has **no evidence of active exploitation** of this specific flaw and **no confirmed IOCs** to share.