Vulnerability News

Critical ConnectWise Vulnerabilities Allow Attackers To Inject Malicious Updates

ConnectWise released a critical security update for its Automate platform on October 16, 2025. The patch, version 2025.9, addresses serious flaws in agent communications that could let attackers intercept sensitive data or push malicious software updates.

These vulnerabilities primarily affect on-premises installations, where misconfigurations might expose systems to network-based exploits.

The issues stem from environments where agents rely on unencrypted HTTP traffic or outdated encryption protocols.

A nearby adversary, perhaps on the same local network, could eavesdrop on transmissions or tamper with update downloads, potentially leading to data breaches or full system compromise.

ConnectWise classified the flaws as “Important” in severity, with a moderate priority rating of 2, signaling that while not immediately catastrophic, they warrant swift action due to the risk of real-world targeting.

ConnectWise Vulnerabilities

At the heart of the update are two specific vulnerabilities, detailed below in a breakdown of their technical attributes. Both require adjacent network access but could enable high-impact attacks without user interaction.

CVE IDCWE IDDescriptionBase ScoreVector (CVSS:3.1)
CVE-2025-11492CWE-319Cleartext Transmission of Sensitive Information9.6AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2025-11493CWE-494Download of Code Without Integrity Check8.8AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The first CVE involves transmitting sensitive agent data in plain text, earning a near-perfect score for its potential to leak credentials or operational details across a scope-expanding attack surface.

The second flaw allows code downloads without verifying integrity, opening the door for attackers to substitute legitimate updates with malware.

Affected versions include all prior to 2025.9, impacting thousands of IT service providers who use ConnectWise Automate for remote management.

Remediation is straightforward but urgent. For cloud-hosted instances, ConnectWise has already rolled out the 2025.9 update automatically, ensuring minimal disruption.

On-premises users must manually apply the patch, which enforces HTTPS for all agent interactions and recommends enabling TLS 1.2 to prevent downgrade attacks.

Security experts urge immediate compliance, especially in multi-tenant setups where one compromised agent could ripple across client networks.

This release underscores the ongoing cat-and-mouse game in endpoint management security. As remote work persists, tools like ConnectWise Automate remain prime targets for supply-chain-style assaults.

Organizations should audit their configurations post-update to verify encrypted channels and monitor for anomalous traffic. With exploits potentially emerging soon, delaying the fix could invite unnecessary risks in an already volatile threat landscape.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

1 minute ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

7 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

18 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago