Known vulnerabilities in Automate
Vendor:
ConnectWise
Software:
Automate
Software CPE:
cpe:2.3:a:connectwise:automate:*:*:*:*:*:*:*:*
Website:
https://www.connectwise.com/
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU132088 - Download of Code Without Integrity Check CVE-2026-9089 |
CWE-494 | High | 2026.5 | 21.05.2026 |
SB2026052153 |
||
| #VU126635 - Cleartext Transmission of Sensitive Information CVE-2026-6066 |
CWE-319 | Low | 2026.4 | 21.04.2026 |
SB2026042125 |
||
| #VU117373 - Download of Code Without Integrity Check CVE-2025-11493 |
CWE-494 | High | 2025.9 | 20.10.2025 |
SB2025102015 |
||
| #VU117371 - Cleartext Transmission of Sensitive Information CVE-2025-11492 |
CWE-319 | Medium | 2025.9 | 20.10.2025 |
SB2025102015 |
||
| #VU54351 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2021-32582 |
CWE-89 | Medium | 2021.5 | 24.06.2021 |
SB2021062405 |
||
| #VU54350 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2021-35066 |
CWE-611 | High | 2021.0.6.132 | 24.06.2021 |
SB2021062404 |