Skip to main content

Vendor/product archive

connectwise / automate CVEs

Beta · best-effort

11 CVEs tagged to connectwise / automate3 Critical, 5 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-9089

Published May 21, 2026

The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6066

Published Apr 20, 2026

ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communica…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-11493

Published Oct 16, 2025

The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk whe…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-11492

Published Oct 16, 2025

In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network positio…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-23130

Published Feb 1, 2023

Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the vendor's position is that, by…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23126

Published Feb 1, 2023

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15838

Published Oct 9, 2020

The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15027

Published Jul 16, 2020

ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1