H-ISAC TLP White Vulnerability Bulletin Security Update Released for ConnectWise Automate Vulnerabilities
On October 16, 2025, ConnectWise released a security update to address two high-severity vulnerabilities, CVE-2025-11492 and CVE-2025-11493, that could enable adversary-in-the-middle (AiTM) attacks.
These flaws allow threat actors to intercept sensitive agent communications and inject malicious code or updates, primarily affecting on-premise deployments. While cloud instances have already been updated, all users running affected on-premise versions of ConnectWise Automate are strongly advised to apply the 2025.9 patch as soon as possible to enforce secure communication protocols.
Health-ISAC is sharing this update to increase situational awareness and encourage organizations to assess their level of risk to these vulnerabilities.
View the detailed bulletin below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:
John Riggi
National Advisor for Cybersecurity and Risk, AHA
jriggi@aha.org
(O) +1 202 626 2272