A critical vulnerability, tracked as CVE-2025-11492 with a CVSS score of 9.6, was identified in the ConnectWise Automate Agent, allowing for man-in-the-middle (MitM) attacks due to improper HTTP configuration and lack of enforced encryption in transit. The flaw enables agent communications to be configured over HTTP instead of HTTPS, exposing sensitive agent-server traffic to interception, modification, or replay by an attacker positioned on the network path. Security researchers highlighted that the encryption method used to obfuscate some communications over HTTP was insufficient, prompting ConnectWise to release the Automate 2025.9 patch, which enforces HTTPS for all agent communications. This vulnerability could allow attackers to gain unauthorized access to sensitive information or manipulate agent-server interactions, posing significant risks to managed service providers and their clients. The issue was disclosed publicly in mid-October 2025, with both security advisories and vulnerability databases emphasizing its critical nature. The vulnerability does not allow for remote exploitation without network access, but it significantly increases risk in environments where HTTP is used. ConnectWise responded by updating their software to mandate secure communication channels, thereby mitigating the risk of MitM attacks. The flaw affects all versions of the Automate Agent where HTTP was permitted, though specific affected versions were not detailed in the advisories. Organizations using ConnectWise Automate are urged to apply the latest patches immediately to ensure all agent communications are encrypted. The vulnerability underscores the importance of enforcing secure transport protocols in remote monitoring and management (RMM) tools. Security experts warn that failure to address this issue could result in data breaches, unauthorized command execution, or further compromise of managed endpoints. The incident has prompted broader discussions about the security of RMM platforms and the need for robust verification of agent-server communications. While no active exploitation has been reported at the time of disclosure, the high severity rating reflects the potential impact if left unremediated. ConnectWise has provided guidance for customers to verify their configurations and ensure compliance with the new security requirements. The vulnerability is distinct from, but related to, another flaw (CVE-2025-11493) affecting the self-update verification mechanism, which is mitigated by enforcing HTTPS as addressed in CVE-2025-11492.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Public reporting described CVE-2025-11492 as a critical ConnectWise Automate flaw with a CVSS score of 9.6. The report said the issue could allow a man-in-the-middle attack against remote monitoring and management agents.
A high-severity vulnerability, CVE-2025-11492, affecting ConnectWise Automate was publicly disclosed. The flaw involves HTTP configuration and encryption in transit and was later described as enabling a man-in-the-middle attack against RMM agents.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.