CVE-2026-9089Patch(connectwise / automate)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch connectwise automate systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-494

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • automate

Threat summary

  • Patch or workaround signal is available
  • 13 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 12 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 6d ago at 3 mentions (2026-05-22); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Products
automate

Deep dive

Activity timeline13 mentions / 7d
01223Mentions · 2026-05-22: 3Mentions · 2026-05-24: 2Mentions · 2026-05-25: 1Mentions · 2026-05-26: 3Mentions · 2026-05-27: 2Mentions · 2026-06-02: 1Mentions · 2026-06-07: 1Patch / Workaround · 2026-05-22: 3Patch / Workaround · 2026-05-24: 2Patch / Workaround · 2026-05-25: 1Patch / Workaround · 2026-05-26: 2Technical Details · 2026-05-22: 3Technical Details · 2026-05-24: 2Technical Details · 2026-05-25: 1Technical Details · 2026-05-26: 3Technical Details · 2026-05-27: 2Technical Details · 2026-06-02: 105-2205-2405-2505-2605-2706-0206-07
Signal classification3 categories
Patch
861.5%
Disclosure
430.8%
General
17.7%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-05-223
Patch3
2026-05-242
Patch2
2026-05-251
Patch1
2026-05-263
Disclosure1Patch2
2026-05-272
Disclosure2
2026-06-021
Disclosure1
2026-06-071
General1
Full discourse13 posts
  • elhacker.NET@elhackernet
    Disclosure

    Vulnerabilidad de ConnectWise Automate permite saltar controles de seguridad ConnectWise ha revelado una vulnerabilidad de seguridad de alto impacto en su plataforma Automate (identificada como CVE-2026-9089), Puntuación CVSS de 8.8, lo que subraya su gravedad potencial. https://blog.elhacker.net/2026/05/vulnerabilidad-de-connectwise-automate.html

    Post summary

    The text announces a high‑impact vulnerability (CVE‑2026‑9089) in ConnectWise Automate, giving its CVSS score and noting the potential to bypass security controls.

    000601.4K
    140.9K followersView on X
  • yousukezan@yousukezan
    Patch

    ConnectWise Automateに深刻な脆弱性「CVE-2026-9089」が見つかった。エージェント更新処理を悪用されると、不正コードをクライアント端末へ配布される恐れがある。 問題はConnectWise Automateのプラグイン読み込みと自己更新機能に存在する。「コード整合性検証なしでのダウンロード」に分類され、更新コンポーネントの完全性確認が不十分だった。攻撃者はこの欠陥を悪用し、悪意あるバイナリを正規更新として実行させられる可能性がある。 CVSSスコアは8.8で、高危険度として扱われている。ConnectWiseは「機密データを侵害し得る脆弱性」と説明しているが、現時点で大規模攻撃の兆候は確認されていない。ただし、特定ネットワーク条件下では完全なコード実行につながる恐れがある。 クラウド版については、既に最新修正版への自動更新が完了しており、利用者側の追加対応は不要となっている。一方、オンプレミス版利用者は手動で「2026.5」リリースへ更新する必要がある。 修正版では、すべての更新コンポーネントに対する整合性検証が強化された。ConnectWiseは通常の変更管理スケジュールより優先してアップデートを実施し、30日以内に適用を完了するよう推奨している。 https://securityonline.info/connectwise-automate-vulnerability-cve-2026-9089/

    Post summary

    CVE‑2026‑9089 exposes a high‑severity remote code execution flaw in ConnectWise Automate's update mechanism; no widespread exploitation yet, but patches are available and administrators are urged to apply them promptly.

    000311.6K
    14.5K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: ConnectWise patches CVE-2026-9089 in Automate RMM, CVSS 8.8 flaw in versions prior to 2026.5 allowing integrity check bypass and potential unauthorized code execution. https://threatcluster.io/cluster/connectwise-automate-vulnerability-allows-code-execution-byp-e63aea49

    Post summary

    ConnectWise has released a patch for the high‑severity CVE‑2026‑9089 in Automate RMM, which allows integrity check bypass and potential remote code execution; no evidence of active exploitation or PoC is provided.

    00010144
    279 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    CVE-2026-9089 in ConnectWise Automate: CWE-494, agent updates processed without integrity check. RMM update-bypass is the Kaseya-class vector - one push hits every managed endpoint. On-prem needs manual patching. https://purple-ops.io/blog/connectwise-automate-cve-2026-9089 https://t.co/vKIG7YpIbw

    Post summary

    The post highlights CVE‑2026‑9089 in ConnectWise Automate, details an integrity‑check bypass in agent updates, and notes that on‑prem installations require manual patching.

    00010157
    575 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    ConnectWise released a fix for a ConnectWise Automate vulnerability (CVE-2026-9089). Learn about the code download flaw and how to patch it now. #Cybersecurity #ConnectWise #Vulnerability #PatchTuesday #Infosec #CWE494 https://securityonline.info/connectwise-automate-vulnerability-cve-2026-9089/ https://t.co/3ykxwC3NCf

    Post summary

    The tweet announces the release of a patch for CVE-2026-9089, detailing a code download flaw in ConnectWise Automate and urges users to apply the fix.

    00010548
    12.5K followersView on X
  • Hephaestvs@Vulcanux_
    Patch

    csirt_it: #Rilevata vulnerabilità per ConnectWise Automate CVE-2026-9089 con gravità “alta” Rischio: 🟠 Tipologia: 🔸 Remote Code Execution 🔗https://www.acn.gov.it/portale/w/rilevata-vulnerabilita-per-connectwise-automate 🔄 Aggiornamenti disponibili 🔄 https://t.co/wiqIQKfsah

    Post summary

    The tweet highlights a high‑severity Remote Code Execution vulnerability (CVE‑2026‑9089) in ConnectWise Automate and indicates that updates or patches are available, but it does not provide PoC, exploit code, or evidence of active exploitation.

    0001048
    614 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-9089: ConnectWise Automate Agent Update Verification Flaw - What It Means for Your Business and How to Respond https://hubs.li/Q04kqdvH0

    Post summary

    The headline announces a ConnectWise Automate Agent update verification flaw (CVE-2026-9089) and hints at business impact mitigation, but lacks concrete evidence of exploits, patches, or technical details.

    0000025
    31 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    ConnectWise Automate の脆弱性 CVE-2026-9089 が FIX:コード検証不備とネットワーク全体への侵害 https://iototsecnews.jp/2026/05/26/connectwise-automate-flaw-allows-hackers-to-evade-security-controls/ 今回の脆弱性 CVE-2026-9089 は、アップデートの仕組みに起因します。プログラムが新しい部品をダウンロードして読み込むときに、それが本当に正しいファイルであることを確認する、”整合性検証” というチェックが不十分な状態で実行されてしまうという問題が生じています。このチェックのギャップを突かれると、悪意のプログラムが読み込まれる危険性があります。特に、運用管理ツールは多くのコンピュータと繋がっているため、一つの不具合が全体に広がってしまう性質を持っています。ご利用のチームは、ご注意ください。 #Automate #ConnectWise #CVE20269089 #Vulnerability

    Post summary

    The text discloses CVE-2026-9089 affecting ConnectWise Automate’s update mechanism, where inadequate integrity checks can allow loading of malicious code and thus pose a risk to all connected networks.

    0000068
    491 followersView on X
  • sea-are-pea@seaarepea
    Disclosure

    #ITSecurity ConnectWise Automate Vulnerability Could Allow Security Check Bypass and RCE | eSecurity Planet https://www.esecurityplanet.com/threats/connectwise-automate-vulnerability-could-allow-security-check-bypass-and-rce/ ConnectWise disclosed CVE-2026-9089 affecting Automate on-premises versions prior to 2026.5.

    Post summary

    ConnectWise has disclosed CVE‑2026‑9089, a vulnerability in Automate on‑premises that could allow a security‑check bypass and remote code execution on versions prior to 2026.5.

    0000037
    72 followersView on X
  • UNDERCODE NEWS@UndercodeNews
    Disclosure

    🚨 #CVE-2026-9089 in ConnectWise Automate Exposes MSP Networks to Remote Code Execution via #Update Integrity Flaw + Video -Fact Checker: ✅: 3 ❌: 0 || 3/3 http://undercodenews.com/cve-2026-9089-in-connectwise-automate-exposes-msp-networks-to-remote-code-execution-via-update-integrity-flaw-video/

    Post summary

    The tweet announces CVE‑2026‑9089 affecting ConnectWise Automate, exposing MSP networks to remote code execution through an update integrity flaw, accompanied by a video demonstration, with no mention of exploit code, active use, or patch.

    0000057
    866 followersView on X
  • ThreadLinqs@threadlinqs
    Patch

    NEW THREAT INTEL: ConnectWise Automate CVE-2026-9089 - Unsigned plugin/update RCE (CVSS 8.8). Patch to 2026.5. https://intel.threadlinqs.com/threat/TL-2026-0588 #ThreatIntel #RMM #CVE https://t.co/kKYvvpgD9l

    Post summary

    Threat intel alert on ConnectWise Automate CVE-2026-9089, an unsigned plugin update RCE with CVSS 8.8, and notes that patching to 2026.5 mitigates the vulnerability.

    0000075
    51 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-9089 (CVSS 8.8) impacts ConnectWise Automate Agent authentication during plugin and update processes. Organizations using Automate should apply the 2026.5 release without delay. https://nvd.nist.gov/vuln/detail/CVE-2026-9089 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning

    Post summary

    The tweet announces CVE-2026-9089, a high‑severity authentication flaw in ConnectWise Automate Agent, and urges users to immediately install the 2026.5 patch.

    0000064
    81 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH Severity: CVE-2026-9089 (CVSS 8.8) ConnectWise Automate Agent fails to verify component authenticity during plugin loading & self-updates. Patch to v2026.5 immediately. CWE-494: Download of Code Without Integrity Check #CVE #Vulnerability #PatchNow https://t.co/mef1K4TwLO

    Post summary

    High‑severity CVE‑2026‑9089 in ConnectWise Automate Agent fails to verify component authenticity; patch to v2026.5 is urgently recommended.

    0000055
    30 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appconnectwiseautomate---

Explore more