216.73.216.6

CVE-2026-6066

· Published 20/04/2026 16:16 · Modified 20/04/2026 19:05

Labels: CVE-2026-6066 2026-04-207d616e1a-3288-43b1-a0dd-0a65d3e70a49CVE-2026-6066CWE-319

Essential information

Published
20/04/2026 16:16
Modified
20/04/2026 19:05
Author
Creator
CVSS
7.1 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CVSS metrics

Description

ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based interception of Solution Center traffic in Automate deployments. The issue has been resolved in Automate 2026.4 by enforcing secure communication for affected Solution Center connections.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
7d616e1a-3288-43b1-a0dd-0a65d3e70a49
NVD
View on NVD

Affected products (CPE)

ProductCPE
connectwise / automate cpe:2.3:a:connectwise:automate:2026.4:*:*:*:*:*:*:*

References