Threat reportVulnerabilityTL-2026-0588

ConnectWise Automate CVE-2026-9089 — Improper Integrity Validation in Agent Plugin Loading and Self-Update (CWE-494)

highMONITORING

ConnectWise Automate CVE-2026-9089 (TL-2026-0588) is a high-severity software vulnerability scored CVSS 8.8, first published 2026-05-26. It has no confirmed attribution, affects ConnectWise Automate (on-premise), references 1 CVE (CVE-2026-9089), maps to 27 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 17 indicators of compromise.

CVSS
8.8/10High
CVEs
1Referenced vulnerabilities
Techniques
27MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
17Indicators of compromise

Key facts for TL-2026-0588

Threat ID
TL-2026-0588
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
MONITORING
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
managed-service-providers, technology, financial, healthcare, government, education, retail, manufacturing, legal, professional-services
Target regions
North America, Europe, Asia-Pacific, Latin America, Global
Detection rules
9
Indicators of compromise
17

Malware and tooling in ConnectWise Automate CVE-2026-9089

Malware and tooling: Connectwise Automate (LabTech)

How ConnectWise Automate CVE-2026-9089 works

ConnectWise Automate agent versions before 2026.5 fail to fully verify the authenticity of components retrieved during plugin loading and self-update operations (CWE-494). A network-adjacent attacker capable of intercepting or tampering with agent traffic can substitute malicious plugin DLLs or update payloads, achieving unauthorized code execution under the agent service. Cloud-hosted Automate instances were patched automatically by ConnectWise on 2026-05-21; on-premise deployments must upgrade to 2026.5.

## Overview

CVE-2026-9089 is a high-severity integrity-validation flaw in the ConnectWise Automate Remote Monitoring and Management (RMM) agent, disclosed in ConnectWise security bulletin dated 2026-05-21 and assigned CVSS 3.1 base score 8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The weakness, classified CWE-494 (Download of Code Without Integrity Check), affects two distinct but related agent subsystems: dynamic plugin loading and the agent's self-update workflow. In both flows, downloaded components could be processed and executed without full cryptographic verification of authenticity or integrity prior to load.

## Root Cause

The ConnectWise Automate Windows agent (LTSvc / Labtech) periodically polls its configured Automate server for management commands, plugin payloads, and agent self-updates. The vulnerable code paths accept binary components — DLL plugins and updater executables — over the agent communication channel and load or execute them on disk without enforcing a strict signature or hash check against an authoritative manifest. Where partial validation existed, it could be bypassed under certain conditions, allowing tampered components to reach the load step. The 2026.5 release introduces enhanced integrity verification across all agent components, ensuring every dynamically loaded module is validated before execution.

## Attack Model

The CVSS vector AV:A (Adjacent Network) reflects that exploitation requires the attacker to be positioned on a network path the agent traverses to reach its Automate control server — for example, the same LAN as a managed endpoint, an upstream router, a misconfigured TLS interception proxy, or a hostile network the endpoint connects through (open Wi-Fi, compromised corporate VPN concentrator, malicious cloud middlebox). With this position the attacker can perform adversary-in-the-middle (T1557) against the agent's HTTP(S) update poll — using ARP poisoning, DHCP/DNS spoofing, BGP hijack, or compromised intermediate proxy — and respond to the agent's plugin or update request with a tampered binary. Because the integrity check is incomplete or bypassable, the agent loads the attacker-controlled component as if it were vendor-signed, yielding code execution under the LTSvc service account, which on Windows endpoints runs as SYSTEM by default. No user interaction (UI:N) and no prior privileges (PR:N) on the endpoint are required.

## Supply-Chain and MSP Blast Radius

ConnectWise Automate is one of the most widely deployed RMM platforms in the Managed Service Provider ecosystem. A single Automate server typically manages hundreds to tens of thousands of endpoints across many downstream customer tenants. An attacker who gains an adjacent-network position relative to even one MSP-managed endpoint can use this flaw as a foothold; an attacker who compromises an intermediate network element along a common path (transit provider, redirector, compromised CDN edge) could potentially affect many endpoints simultaneously. Successful exploitation grants SYSTEM-level RMM agent control, which by design has privileged remote command execution, file transfer, and software deployment across managed endpoints — the same attack surface abused in the Kaseya VSA / REvil supply-chain ransomware campaign of 2021 and in prior ConnectWise ScreenConnect zero-day campaigns (e.g. CVE-2024-1709 SlashAndGrab).

## Exploit Chain

1. Initial position — Attacker establishes an adjacent network position (T1557.002 ARP cache poisoning, T1557.003 DHCP spoofing, T1071.001 hostile proxy) on a path between the Automate agent and its server, or compromises a TLS-terminating middlebox. 2. Interception — Attacker observes the agent's periodic poll (default check-in interval ~60 seconds) to the Automate server endpoint, identifying plugin-pull or self-update requests. 3. Payload substitution — Attacker responds with a tampered DLL plugin or updater binary in place of the legitimate vendor payload (T1195.002 Compromise Software Supply Chain, T1574 Hijack Execution Flow). 4. Bypass of integrity check — Vulnerable agent code path either skips the integrity check entirely for the affected component class, accepts a forged or weak hash, or honors a server-supplied manifest the attacker controls. 5. Code execution — Agent loads the tampered DLL into LTSvc.exe or executes the updater under LocalSystem (T1129 Shared Modules; T1059 Command and Scripting Interpreter via plugin logic). 6. Persistence — Malicious payload installs as an LTSvc plugin, registers a scheduled task, creates a new Windows service, or modifies a Run key (T1543.003 Create or Modify System Process: Windows Service; T1547.001 Registry Run Keys). 7. Defense evasion — Plugin runs inside the trusted RMM process, evading EDR rules that allowlist LTSvc.exe activity (T1218 System Binary Proxy Execution, T1027 Obfuscated Files or Information). 8. Lateral movement and follow-on impact — Attacker pivots through the Automate management plane to push commands, scripts, or installers to other managed endpoints (T1021 Remote Services; T1072 Software Deployment Tools), enabling broad ransomware staging (T1486), credential theft (T1003), or data exfiltration (T1041).

## Affected Products

- ConnectWise Automate, all versions prior to 2026.5 (on-premise deployments). - ConnectWise Automate Cloud — automatically patched by ConnectWise on or before 2026-05-21.

## Detection Considerations

No indicators of compromise have been published by ConnectWise as of the disclosure date. Defensive telemetry should focus on (a) unexpected child processes of LTSvc.exe, especially scripting hosts (powershell.exe, cmd.exe, wscript.exe, cscript.exe), (b) unsigned or anomalously signed DLLs in C:\Windows\LTSvc\Plugins\, (c) agent self-update events occurring outside change windows, (d) ARP/DHCP/DNS anomalies on networks hosting Automate-managed endpoints, and (e) TLS certificate mismatches on the agent-server channel where TLS interception is not authorized.

## Remediation

On-premise: upgrade ConnectWise Automate to 2026.5 within 30 days per the vendor priority-2 guidance. Cloud: no action required, already patched. Compensating controls until patched include enforcing strict network segmentation around RMM agents, validating that agent-server TLS chains are pinned to vendor CAs only, disabling TLS interception of RMM traffic, and increasing EDR sensitivity to LTSvc.exe child process anomalies.

MITRE ATT&CK techniques used in TL-2026-0588

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services; T1072 Software Deployment Tools

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1218 System Binary Proxy Execution

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1543.003 Create or Modify System Process: Windows Service; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Execution

T1059 Command and Scripting Interpreter; T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1129 Shared Modules

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer

Discovery

T1082 System Information Discovery

Initial Access

T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1195.002 Supply Chain Compromise: Compromise Software Supply Chain; T1199 Trusted Relationship

Impact

T1486 Data Encrypted for Impact

defense-impairment

T1553.002 Subvert Trust Controls: Code Signing

Credential Access

T1557 Adversary-in-the-Middle; T1557.002 Adversary-in-the-Middle: ARP Cache Poisoning; T1557.003 Adversary-in-the-Middle: DHCP Spoofing

stealth

T1574 Hijack Execution Flow; T1574.001 DLL

Affected products and versions in ConnectWise Automate CVE-2026-9089

  • ConnectWise — Automate (on-premise)
    Vulnerable versions: < 2026.5
    Fixed in: 2026.5
  • ConnectWise — Automate (cloud-hosted)
    Vulnerable versions: pre-2026-05-21 cloud builds
    Fixed in: 2026.5 (auto-updated by vendor)
  • ConnectWise — Automate Agent (LTSvc / Labtech client)
    Vulnerable versions: agent builds shipped with Automate < 2026.5
    Fixed in: agent build shipped with Automate 2026.5

Remediation for ConnectWise Automate CVE-2026-9089

Patches

  • Apply ConnectWise Automate 2026.5 (on-premise). Reference: ConnectWise Automate Release Notes 2026.5.
  • Cloud-hosted instances already updated by ConnectWise on or before 2026-05-21.

Immediate actions

  • Inventory all on-premise ConnectWise Automate server and agent versions; identify any below 2026.5.
  • Verify cloud-hosted Automate instances are reporting 2026.5 or later in the admin console.
  • Restrict Automate agent egress to known vendor and self-hosted server endpoints only; block agent-to-internet plugin pulls through arbitrary intermediaries.
  • Disable TLS interception (SSL inspection) for the agent-to-server channel where it cannot be tightly authenticated.
  • Tighten EDR rules to alert on scripting-host child processes spawned by LTSvc.exe and on unsigned DLL loads from C:\Windows\LTSvc\Plugins\.

Workarounds

  • If immediate patching is not possible, isolate Automate-managed endpoints onto network segments that cannot be reached by adversary-in-the-middle vantage points (no shared LAN with untrusted devices, no transit through untrusted proxies).
  • Disable plugin auto-load and pause automatic agent self-update where the agent supports it, until 2026.5 is deployed.

Longer-term hardening

  • Move on-premise Automate deployments behind a hardened reverse proxy with mutual TLS to the agent fleet.
  • Adopt strict network segmentation between RMM agents and untrusted networks (no agents on guest or open Wi-Fi without IPsec).
  • Deploy host-based DLL allowlisting for LTSvc.exe plugin directory.
  • Implement detection use-cases for agent self-update events outside approved change windows.
  • Periodically attest LTSvc plugin directory contents against a vendor-supplied manifest of expected signatures.

CVEs associated with ConnectWise Automate CVE-2026-9089

CVE-2026-9089

Weaknesses (CWE) in ConnectWise Automate CVE-2026-9089

CWE-494

Timeline of ConnectWise Automate CVE-2026-9089

  • NVD record published for CVE-2026-9089 with status 'Undergoing Analysis'; weakness mapped to CWE-494; vendor advisory linked as primary reference.
  • ConnectWise auto-updates all cloud-hosted Automate instances to 2026.5, closing the integrity-validation gap for managed customers.
  • CVE-2026-9089 assigned and published by ConnectWise CNA (source ID 7d616e1a-3288-43b1-a0dd-0a65d3e70a49) with CVSS 3.1 vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, base score 8.8.
  • ConnectWise publishes security bulletin disclosing CVE-2026-9089 affecting Automate agent plugin loading and self-update mechanisms; rates Important / Priority 2 Moderate; releases Automate 2026.5 with enhanced integrity verification.
  • Threadlinqs Intelligence ingests CVE-2026-9089 as TL-2026-0588 for full analysis, detection development, and simulation.
  • Cyber Security News publishes external coverage 'ConnectWise Automate Vulnerability Let Attackers Bypass Security Checks' summarizing the bulletin, attack model, and MSP supply-chain risk.
  • As of 2026-05-29, CVE-2026-9089 (ConnectWise Automate CWE-494 integrity flaw, CVSS 8.8) is patched in 2026.5 with cloud instances auto-updated, no public PoC, no in-the-wild exploitation, and not in CISA KEV. It remains MONITORING because on-premise MSPs are still inside the open 30-day patch window and ConnectWise's RMM has a history of post-disclosure exploitation.
  • Vendor-recommended 30-day remediation window for on-premise Automate operators to deploy 2026.5 (Priority 2).

Sources cited for ConnectWise Automate CVE-2026-9089

Detection coverage for TL-2026-0588

As of 2026-05-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0588 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
17 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats