ConnectWise Security Update – 19 October 2025

ConnectWise has released a security update to fix multiple vulnerabilities in ConnectWise Automate.

The addressed vulnerabilities could allow the attacker to perform adversary-inthe- middle (AitM) attacks to view or modify traffic or substitute malicious updates and obtain sensitive information by configuring agents to communicate over HTTP instead of HTTPS.

Sample of the addressed vulnerabilities:

ConnectWise Cleartext Transmission of Sensitive Information Vulnerability (CVE-2025-11492):

  • CVSS: 9.6
  • Attack Vector: Adjacent
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Adversary-in-the-Middle (AitM) Attack
Vulnerabilities
  • CVE-2025-11492
  • CVE-2025-11493
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

ConnectWise Security Advisory

References