← Vulnerability feed

Vulnerability record · CVE-2026-9089 · published 21 May 2026

CVE-2026-9089: Connectwise automate download of code without integrity check vulnerability

Connectwise · Automate

The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.

8.8 CVSS 3.1 High EPSS 0.21% · top 89.7% CWE-494 · Download of code without integrity check
8.8CVSS 3.1 base score
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
23 Jul 2026Last modified by NVD

Description

The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-9089 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-35066Connectwise automate xml external entity (xxe) vulnerabilityAn XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.EPSS 1.1%9.8CVE-2020-15027Connectwise automate improper authentication vulnerabilityConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attem…EPSS 1.3%8.8CVE-2020-15838Connectwise automate incorrect permission assignment vulnerabilityThe Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.EPSS 1.2%8.1CVE-2023-47257Connectwise automate code injection vulnerabilityConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.EPSS 1.0%7.5CVE-2025-11493Connectwise automate download of code without integrity check vulnerabilityThe ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integra…EPSS 0.23%7.5CVE-2025-11492Connectwise automate cleartext transmission vulnerabilityIn the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man…EPSS 0.21%7.1CVE-2026-6066Connectwise automate cleartext transmission vulnerabilityConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where cert…EPSS 0.13%6.1CVE-2023-23126Connectwise automate clickjacking vulnerabilityConnectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended action…EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2026-9089), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.