CVE-2026-6066: Unencrypted Client‑Server Communication in ConnectWise Automate™ Solution Center
ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based interception of Solution Center traffic in Automate deployments. The issue has been resolved in Automate 2026.4 by enforcing secure communication for affected Solution Center connections.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ConnectWise Automateto a version that resolves this vulnerability.Fixed in 2026.4 - Configuration
On-Premise deployments: ensure secure Solution Center client-to-server communications are established using HTTPS on port 8484 (to enforce transport-layer encryption for affected Solution Center connections).
ConnectWise Automate Solution Center Service HTTPS / secure communication port = 8484 - Configuration
Configure the antivirus/endpoint exclusions specified in "Automate Antivirus Exclusions for Windows" (ConnectWise documentation) to prevent antivirus/protection products from interfering with the Automate patch installer or service startup.
Antivirus/Endpoint protection on Automate server(s) Automate Antivirus exclusions = per ConnectWise documentation - Compensating control
On-Premise: ensure the LTShare has at least 1 GB of free space prior to installation/upgrade.
- Compensating control
If you encounter issues during installation or completing the update, follow ConnectWise guidance for those scenarios (per ConnectWise documentation) rather than skipping required update steps.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6066?
CVE-2026-6066 has been assigned a severity level that indicates a significant risk due to the potential for unencrypted client-server communication.
How do I fix CVE-2026-6066?
To fix CVE-2026-6066, users should update to the latest version of ConnectWise Automate as provided in the security update.
What impact does CVE-2026-6066 have on my system?
CVE-2026-6066 allows for the possibility of sensitive data being transmitted without encryption, exposing it to interception during client-server communications.
Is CVE-2026-6066 only affecting older versions of ConnectWise Automate?
Yes, CVE-2026-6066 primarily affects ConnectWise Automate versions up to 2026.4 and requires an upgrade to mitigate the vulnerability.
When was CVE-2026-6066 disclosed?
CVE-2026-6066 was disclosed on April 20, 2026, as part of a security bulletin by ConnectWise.