Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical ConnectWise Vulnerabilities Allow Attackers To Inject Malicious Updates

ConnectWise has issued a critical security update for its Automate platform as of Thu, Oct 16, 2025. The patch, version 2025.9, addresses significant vulnerabilities in agent communications, which could allow attackers to intercept sensitive data or…

ConnectWise has issued a critical security update for its Automate platform as of Thu, Oct 16, 2025. The patch, version 2025.9, addresses significant vulnerabilities in agent communications, which could allow attackers to intercept sensitive data or introduce malicious software updates.

The vulnerabilities predominantly impact on-premises installations, particularly where systems are configured to utilize unencrypted HTTP traffic or outdated encryption protocols. Such configurations may expose systems to network-based exploits.

The vulnerabilities require adjacent network access and could lead to severe attacks without user interaction. An adversary on the same local network could potentially eavesdrop on data transmissions or tamper with update downloads, risking data breaches or full system compromise.

ConnectWise has categorized these vulnerabilities as "Important" with a moderate priority rating, indicating a need for prompt action.

ConnectWise has issued a critical security update for its Automate platform as of Thu, Oct 16, 2025.
Sarah Dawson · Thehackingpost

CVE-2025-11492: Involves the cleartext transmission of sensitive information, with a CVSS base score of 9.6. CVE-2025-11493: Concerns the download of code without integrity checks, with a CVSS base score of 8.8.

Both vulnerabilities affect versions prior to 2025.9 and impact numerous IT service providers utilizing ConnectWise Automate for remote management.

For cloud-hosted instances, ConnectWise has already deployed the 2025.9 update automatically. On-premises users are required to manually apply the patch, which enforces HTTPS for all agent interactions and recommends enabling TLS 1.2 to mitigate downgrade attacks.

Advertisement

It is advised to conduct an audit of configurations post-update to confirm encrypted channels and monitor for unusual traffic patterns. Implementing these measures is crucial to mitigate risks in a volatile threat landscape.

For further information on the security update, please visit the official ConnectWise security bulletin .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories