ConnectWise fixes Automate bug allowing AiTM update attacks
ID: 39e22051-a5af-539c-aa21-808b23cf96f8
STIX ID: report--39e22051-a5af-539c-aa21-808b23cf96f8
Feed Name: Bleeping Computer
Threat Score
ConnectWise released patches for two high-severity vulnerabilities in Automate (CVE-2025-11492 — 9.6; CVE-2025-11493 — 8.8) that can allow agents to communicate in cleartext and permit update packages to be accepted without integrity checks, enabling AiTM interception and malicious update injection; cloud instances have been updated to 2025.9 and on-premise administrators are urged to install the fix promptly, while no active exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
