Sitecore ViewState exploitation and ScreenConnect machine-key hardening
Case score 57
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 57
- Main story score
- 57
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 2
- Exploitation Wave Core Sitecore exploitation wave with active use of exposed ASP.NET machine keys and follow-on intrusion activity. main
- Vulnerability ScreenConnect CVE-2026-3564 shows a related machine-key verification risk, but active exploitation is not confirmed. context
- Security Patch Release ScreenConnect 26.1 hardens machine-key handling and gives defender context for the same exposure class. context
Overview
Latest development Open development history ScreenConnect 26.1 hardens machine-key handling ConnectWise says ScreenConnect 26.1 strengthens machine-key protection with encrypted storage and improved handling, with cloud users moved to the safe version automatically and on-premises administrators told to upgrade as soon as possible.
-
ConnectWise warns of ScreenConnect CVE-2026-3564
ConnectWise warns ScreenConnect customers about CVE-2026-3564, a critical cryptographic signature verification flaw affecting ScreenConnect versions before 26.1 that could let an attacker abuse ASP.NET machine keys for unauthorized session authentication, leading to unauthorized access and privilege escalation.
-
ConnectWise warns ScreenConnect customers about CVE-2026-3564
ConnectWise warned ScreenConnect customers about CVE-2026-3564, a cryptographic signature verification vulnerability affecting ScreenConnect versions before 26.1 that could let an attacker abuse ASP.NET machine keys for unauthorized session authentication, unauthorized access, and privilege escalation. The vendor said researchers observed attempts to abuse disclosed ASP.NET machine key material in the wild, but it had no evidence of active exploitation in ConnectWise-hosted ScreenConnect and no confirmed IOCs to share. ScreenConnect 26.1 adds stronger machine-key protection, and on-premises administrators are told to upgrade as soon as possible while also tightening access to configuration files and secrets, checking logs for unusual authentication activity, protecting backups and old data snapshots, and keeping extensions up to date.
-
Sitecore zero-day CVE-2025-53690 is exploited through exposed ASP.NET machine keys
A critical Sitecore zero-day tracked as CVE-2025-53690 was under active ViewState deserialization exploitation against Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce deployments, with attackers leveraging an exposed ASP.NET machine key from Sitecore deployment guides from 2017 and earlier to achieve remote code execution.
-
Mandiant disrupts an active ViewState deserialization attack on a Sitecore server
Mandiant Threat Defense said it discovered an active ViewState deserialization attack affecting Sitecore deployments that leveraged a sample machine key exposed in Sitecore deployment guides from 2017 and earlier, then initiated rapid response and successfully disrupted the attack on a Sitecore server before the full attack cycle could be observed.