Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6066

24
FAUCET Score

CVE-2026-6066 is an unencrypted communication vulnerability in ConnectWise Automate's Solution Center that allows certain client-to-server traffic to traverse the network without transport-layer encryption, potentially exposing sensitive data to interception attacks. The vulnerability affects Automate deployments prior to version 2026.4, where the issue has been remediated through enforcement of secure communication protocols. The vulnerability carries a CVSS 3.1 score of 7.1 (HIGH) with a network-based attack vector requiring low complexity and authenticated user privileges. The primary impact is confidentiality compromise (high severity) with minor integrity risk, while availability remains unaffected. The attack requires no user interaction once an authenticated session is established. Current exploitation status indicates minimal community attention and no active weaponization. The vulnerability does not appear on CISA's Known Exploited Vulnerabilities catalog, and the EPSS score of 0.00013 reflects extremely low probability of exploitation in the wild. Organizations running Automate versions prior to 2026.4 should prioritize patching to eliminate the unencrypted communication pathway.

Impacted Technologies

VendorProductVersion(s)CPE
< 2026.4CPE matchmatch criteria
cpe:2.3:a:connectwise:automate:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.08%
Probability of exploitation in next 30 days
EPSS Percentile
0.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0008 is in the 0th percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

connectwise.com / company/trust/security-bulletins/2026-04-20-connectwise-automate-bulletin
Vendor Advisory