Automate
Vendor:
First CVE: Jul 16, 2020 · Active for 6 years
11
Total CVEs
More Total CVEs than 89% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Automate over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 16, 2020
6 years ago
Most Recent CVE
May 21, 2026
65 days ago
CVE Severity & Scoring
Automate11 CVEs
27%
55%
18%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (9.1%)
Network7 (63.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (27.3%)
Attack Complexity
Low7 (63.6%)
High4 (36.4%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low3 (27.3%)
High0 (0.0%)
None8 (72.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9089HIGH The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate | May 21, 2026 | 8.8 | 39 | NO | NO |
CVE-2020-15027CRITICAL ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 | Jul 16, 2020 | 9.8 | 30 | NO | NO |
CVE-2025-11492HIGH In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position | Oct 16, 2025 | 7.5 | 29 | NO | NO |
CVE-2021-35066CRITICAL An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132. | Jun 21, 2021 | 9.8 | 28 | NO | NO |
CVE-2025-11493HIGH The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk wher | Oct 16, 2025 | 7.5 | 27 | NO | NO |
CVE-2026-6066HIGH ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communicat | Apr 20, 2026 | 7.1 | 24 | NO | NO |
CVE-2023-47257HIGH ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages. | Feb 1, 2024 | 8.1 | 23 | NO | NO |
CVE-2020-15838HIGH The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions. | Oct 9, 2020 | 8.8 | 22 | NO | NO |
CVE-2023-23130MEDIUM Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the vendor's position is that, by | Feb 1, 2023 | 5.9 | 21 | NO | NO |
CVE-2023-47256MEDIUM ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings | Feb 1, 2024 | 5.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Automate
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2022.11 | 2 | 6.0 | 0.4% | 0 | 0 |