02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: ConnectWiseUnencrypted Client‑Server Communication in ConnectWise Automate™ Solution Center
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Assessed, none found. CISA's assessment recorded neither public exploit code nor evidence of exploitation when it was made.
- SSVC decision
- ExploitationnoneCISA recorded no public exploit code and no evidence of exploitation.
- AutomatablenoAt least one step from reconnaissance to exploitation cannot be reliably automated.
- Technical ImpactpartialSuccessful exploitation gives limited control of the vulnerable component.
CISA publishes the decision points, not a final SSVC decision. The decision also depends on mission and well-being impact, which is a property of your deployment rather than of the vulnerability.- EPSS probability
- 0.08% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 0.3% of scored records. A rank, not a probability.
- NVD base score
- 7.1 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- NVD analysis status
- Analyzed. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.2
- Published
- 2026-04-20 15:26Z4 MO AGO
- Last updated
- 2026-04-20 16:13Z4 MO AGO
- Reserved
- 2026-04-10
- Assigning CNA
- ConnectWise
- Record state
- PUBLISHED
- Severity
- High (CVSS 7.1)
- CNA CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Weaknesses
- CWE-319Cleartext Transmission of Sensitive InformationBase
- Data version
- 5.2
- Document digest
- 9cde9e2d83456fea757359b10515f0f37598d84fb1840f89b0fe9c200fa195fe
05 Affected products
PAIRS: 1VendorProductVersionsPlatforms
ConnectWiseAutomateAll versions prior to 2026.4— SRC: CNA
Remediation
Cloud: No action is required.
On-Premise: Apply the 2026.4 release.
For instruction on updating to the newest release, please
reference this doc: Automate Release Notes Version 2026 - ConnectWise https://docs.connectwise.com/ConnectWise_Automate_Documentation/100/Automate_Release_Notes_Version_2026
After applying the update, on-premises customers must
ensure the following configurations are in place:
* An SSL certificate is bound to the Solution
Center on port 8484 to establish secure communication. Refer to the ConnectWise documentation for configuration steps: Solution Center Client and
Service HTTPS Update - ConnectWise
* In some environments, antivirus or endpoint
protection products may interfere with the Automate patch installer or service
behavior during upgrades. If issues are encountered during installation or
startup, refer to the ConnectWise documentation for recommended antivirus
exclusions: Automate Antivirus Exclusions for Windows https://docs.connectwise.com/ConnectWise_Automate_Documentation/060/040/010
* Ensure that the LTShare has a minimum of 1 GB of
free disk space prior to installation.
If you experience issues completing the update or
required configuration steps, please contact ConnectWise
Support for assistance.