ConnectWise has released an urgent security update for its Automate, the popular remote IT management tool used by thousands of service providers around the world. The update (version 2025.9) fixes serious vulnerabilities in agent communicationsthat could allow attackers to intercept sensitive data or even introduce malicious updates through the same distribution mechanisms.

What caused the alarm?
The problems are mainly found in on-premise installations, where incorrect configurations or use of insecure protocols such as HTTP and old encryption standards leave systems exposed to attacks.
In such cases, a malicious actor located on the same local network could intercept transmissions or disrupt update downloads, potentially leading to data breaches or a complete system compromise.
See also: WatchGuard vulnerability allows malicious code execution
ConnectWise rated the vulnerabilities as “Important.” While these are not vulnerabilities that can be exploited remotely without network access, the risk of real-world exploitation is considered high, especially in multi-tenant environments.

ConnectWise: The two most important vulnerabilities being fixed
At the heart of the update are two critical vulnerabilities that threaten the operational integrity of Automate installations:
- CVE-2025-11492 (9.6/10)
Sending data in unencrypted form (plain text) – This is a bug that allows sensitive information to be leakedto anyone with the ability to monitor network traffic.
- CVE-2025-11493 (8.8/10)
Unchecked Code Download – The second flaw concerns the ability to execute unverified update packages. In other words, an attacker could replace legitimate updates with malicious software, installing it on the target system without the administrator realizing it.
Who is affected and what should users do?
All versions prior to 2025.9 are considered vulnerable. The update is mandatory for all customers, with ConnectWise already installing the patch automatically for cloud-based installations, ensuring minimal downtime.
See also: The most serious ASP.NET Core vulnerability discovered by Microsoft
However, on-premise customers will need to perform a manual upgrade. In the meantime, the patch:
- enforces mandatory use of HTTPS,
- enables support for TLS 1.2 and later,
- and disables insecure communication protocols.
Experts recommend installing the update immediately , warning that a compromised agent can be used as a vehicle to transmit malware to other connected networks or clients.

The bigger picture: A constant game of defense
The ConnectWise case highlights the continued vulnerability of remote management tools, which are target for cybercriminals. Because of the access they offer to multiple systems simultaneously, such tools are often used as gateways for supply chain attacks.
The continued reliance of businesses on teleworking and remote support further increases the importance of securing these platforms. A breach in IT management software can have ripple effects, affecting entire customer and provider networks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Vulnerabilities in Cisco Desk, IP and Videophones Allow DoS and XSS Attacks
Preventive measures and good practices
Experts recommend that managers:
- check encryption settings immediately,
- activate monitoring logs for suspicious traffic,
- and ensure that updates only come from verified sources.
In addition, organizations should implement a multi-layered security strategy (defense-in-depth), combining technological measures, staff training, and immediate incident response procedures.
The new ConnectWise update serves as a reminder of the fragility of security in the digital world. A simple configuration error or a late update can be the entry point for a large-scale cyberattack.
With the threat landscape constantly evolving, speed of response and discipline in implementing updates remain the most effective defenses against an invisible, but highly intelligent enemy.
