VendorsConnectWiseautomateany version
Vulnerabilities

ConnectWise Automate any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2020-15027
ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12.
Published 2020-07-16 · Modified
9.8EPSS 0.013
CVE-2021-35066
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
Published 2021-06-21 · Modified
9.8EPSS 0.011
CVE-2025-11492
HTTP Configuration and Encryption in Transit
Published 2025-10-16 · Analyzed
9.6EPSS 0.002
CVE-2020-15838
The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
Published 2020-10-09 · Modified
8.8EPSS 0.012
CVE-2025-11493
Self-Update Verification Mechanism Process in ConnectWise Automate
Published 2025-10-16 · Analyzed
8.8EPSS 0.002
CVE-2026-9089
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.
Published 2026-05-21 · Analyzed
8.8EPSS 0.002
CVE-2023-47257
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
Published 2024-02-01 · Modified
8.1EPSS 0.010
CVE-2026-6066
Unencrypted Client‑Server Communication in ConnectWise Automate™ Solution Center
Published 2026-04-20 · Analyzed
7.1EPSS 0.001
CVE-2023-47256
ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings
Published 2024-02-01 · Modified
5.5EPSS 0.004