logo

ConnectWise Patches Severe Code Execution Flaw in Automate

ID: 8770f52a-a67d-5def-89f9-99c92eb814ef

STIX ID: report--8770f52a-a67d-5def-89f9-99c92eb814ef

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-05-24

Date Updated: 2026-05-24

Author: Ddos

...
...

ConnectWise disclosed a high-severity vulnerability (CVE-2026-9089) in ConnectWise Automate where components can be loaded without full integrity verification, enabling potential execution of malicious binaries; the issue has a CVSS base score of 8.8. Cloud instances were auto-updated by the vendor, while on-premises customers must apply the 2026.5 patch within 30 days to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.