securityonline.info 5/25/2026, 12:03:35 AM · external

ConnectWise Patches Severe Code Execution Flaw in Automate

ConnectWise Patches Severe Code Execution Flaw in Automate
CyberSIXT Evidence Panel
Primary Source docs.connectwise.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THE content discusses a critical security vulnerability (CVE-2026-9089) in ConnectWise Automate software, which allows attackers to bypass security checks during updates. The flaw arises from a lack of integrity checks in the code loading process, posing a risk for running malicious binaries. The vulnerability has a CVSS base score of 8.8, indicating a significant threat. Cloud users are automatically updated, while on-premises administrators must manually apply the patch to enhance security verification. Prompt action is advised to mitigate risks.

View Primary Source Via securityonline.info

Article by CyberSIXT