CVE-2026-6066Patch(connectwise / automate)

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch connectwise automate systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based interception of Solution Center traffic in Automate deployments. The issue has been resolved in Automate 2026.4 by enforcing secure communication for affected Solution Center connections.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-319

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • automate

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-21)
  • 3 total mentions across 2 days

Affected systems

Products
automate

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-20: 1Mentions · 2026-04-21: 2Patch / Workaround · 2026-04-21: 2Technical Details · 2026-04-20: 104-2004-21
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-201
Disclosure1
2026-04-212
Patch2
Full discourse3 posts
  • CVE@CVEnew
    Patch

    CVE-2026-6066 ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-serve… https://www.cve.org/CVERecord?id=CVE-2026-6066

    Post summary

    ConnectWise has released a security update for ConnectWise Automate to fix a behavior in the Solution Center; the post contains no PoC, exploit code, or evidence of active exploitation.

    00010177
    57.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-6066 ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-serve… https://www.cve.org/CVERecord?id=CVE-2026-6066 ----- Traducción: CVE-2026-6066 Co… http://infoflow.cloud`

    Post summary

    The tweet announces that ConnectWise has released a security update for ConnectWise Automate to address CVE‑2026‑6066, without providing technical or exploitation details.

    0000025
    72 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6066 Unencrypted Client-to-Server Communication in ConnectWise Automate Solution Center https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6066

    Post summary

    The text introduces CVE-2026-6066, describing unencrypted client‑to‑server communication in ConnectWise Automate, with no PoC, exploit, patch, or active exploitation information.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appconnectwiseautomate---

Explore more