CVE-2026-6066: Unencrypted Client‑Server Communication in ConnectWise Automate™ Solution Center

Published Apr 20, 2026
·
Updated

ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based interception of Solution Center traffic in Automate deployments. The issue has been resolved in Automate 2026.4 by enforcing secure communication for affected Solution Center connections.

Affected Software

2 affected components
ConnectWise Connectwise Automate<2026.4
ConnectWise Automate<2026.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ConnectWise Automate to a version that resolves this vulnerability.

    Fixed in 2026.4
  2. Configuration

    On-Premise deployments: ensure secure Solution Center client-to-server communications are established using HTTPS on port 8484 (to enforce transport-layer encryption for affected Solution Center connections).

    ConnectWise Automate Solution Center Service HTTPS / secure communication port = 8484
  3. Configuration

    Configure the antivirus/endpoint exclusions specified in "Automate Antivirus Exclusions for Windows" (ConnectWise documentation) to prevent antivirus/protection products from interfering with the Automate patch installer or service startup.

    Antivirus/Endpoint protection on Automate server(s) Automate Antivirus exclusions = per ConnectWise documentation
  4. Compensating control

    On-Premise: ensure the LTShare has at least 1 GB of free space prior to installation/upgrade.

  5. Compensating control

    If you encounter issues during installation or completing the update, follow ConnectWise guidance for those scenarios (per ConnectWise documentation) rather than skipping required update steps.

Event History

Apr 20, 2026
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Aug 7, 58287
Event
via FIRST·02:32 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-6066?

CVE-2026-6066 has been assigned a severity level that indicates a significant risk due to the potential for unencrypted client-server communication.

2

How do I fix CVE-2026-6066?

To fix CVE-2026-6066, users should update to the latest version of ConnectWise Automate as provided in the security update.

3

What impact does CVE-2026-6066 have on my system?

CVE-2026-6066 allows for the possibility of sensitive data being transmitted without encryption, exposing it to interception during client-server communications.

4

Is CVE-2026-6066 only affecting older versions of ConnectWise Automate?

Yes, CVE-2026-6066 primarily affects ConnectWise Automate versions up to 2026.4 and requires an upgrade to mitigate the vulnerability.

5

When was CVE-2026-6066 disclosed?

CVE-2026-6066 was disclosed on April 20, 2026, as part of a security bulletin by ConnectWise.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203