CVE-2025-11492EPSS p9.7%
CVE-2025-11492CVE-2025-11492
connectwise / automate
Description
In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic. Additionally, the encryption method used to obfuscate some communications over the HTTP channel is updated in the Automate 2025.9 patch to enforce HTTPS for all agent communications.
Scoring
| CVSS | 9.6 () |
| Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 0.21% probability of exploitation · percentile 9.7% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-09 |