# ConnectWise Automate CVE-2026-9089 — Improper Integrity Validation in Agent Plugin Loading and Self-Update (CWE-494)

> ConnectWise Automate agent versions before 2026.5 fail to fully verify the authenticity of components retrieved during plugin loading and self-update operations (CWE-494). A network-adjacent attacker capable of intercepting or tampering with agent traffic can substitute malicious plugin DLLs or update payloads, achieving unauthorized code execution under the agent service. Cloud-hosted Automate instances were patched automatically by ConnectWise on 2026-05-21; on-premise deployments must upgrade to 2026.5.

- **Published:** 2026-05-26T00:00:00Z
- **Last reviewed:** 2026-05-26T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0588
- **ID:** TL-2026-0588
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 17 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-9089

## Description

## Overview

CVE-2026-9089 is a high-severity integrity-validation flaw in the ConnectWise Automate Remote Monitoring and Management (RMM) agent, disclosed in ConnectWise security bulletin dated 2026-05-21 and assigned CVSS 3.1 base score 8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The weakness, classified CWE-494 (Download of Code Without Integrity Check), affects two distinct but related agent subsystems: dynamic plugin loading and the agent's self-update workflow. In both flows, downloaded components could be processed and executed without full cryptographic verification of authenticity or integrity prior to load.

## Root Cause

The ConnectWise Automate Windows agent (LTSvc / Labtech) periodically polls its configured Automate server for management commands, plugin payloads, and agent self-updates. The vulnerable code paths accept binary components — DLL plugins and updater executables — over the agent communication channel and load or execute them on disk without enforcing a strict signature or hash check against an authoritative manifest. Where partial validation existed, it could be bypassed under certain conditions, allowing tampered components to reach the load step. The 2026.5 release introduces enhanced integrity verification across all agent components, ensuring every dynamically loaded module is validated before execution.

## Attack Model

The CVSS vector AV:A (Adjacent Network) reflects that exploitation requires the attacker to be positioned on a network path the agent traverses to reach its Automate control server — for example, the same LAN as a managed endpoint, an upstream router, a misconfigured TLS interception proxy, or a hostile network the endpoint connects through (open Wi-Fi, compromised corporate VPN concentrator, malicious cloud middlebox). With this position the attacker can perform adversary-in-the-middle (T1557) against the agent's HTTP(S) update poll — using ARP poisoning, DHCP/DNS spoofing, BGP hijack, or compromised intermediate proxy — and respond to the agent's plugin or update request with a tampered binary. Because the integrity check is incomplete or bypassable, the agent loads the attacker-controlled component as if it were vendor-signed, yielding code execution under the LTSvc service account, which on Windows endpoints runs as SYSTEM by default. No user interaction (UI:N) and no prior privileges (PR:N) on the endpoint are required.

## Supply-Chain and MSP Blast Radius

ConnectWise Automate is one of the most widely deployed RMM platforms in the Managed Service Provider ecosystem. A single Automate server typically manages hundreds to tens of thousands of endpoints across many downstream customer tenants. An attacker who gains an adjacent-network position relative to even one MSP-managed endpoint can use this flaw as a foothold; an attacker who compromises an intermediate network element along a common path (transit provider, redirector, compromised CDN edge) could potentially affect many endpoints simultaneously. Successful exploitation grants SYSTEM-level RMM agent control, which by design has privileged remote command execution, file transfer, and software deployment across managed endpoints — the same attack surface abused in the Kaseya VSA / REvil supply-chain ransomware campaign of 2021 and in prior ConnectWise ScreenConnect zero-day campaigns (e.g. CVE-2024-1709 SlashAndGrab).

## Exploit Chain

1. Initial position — Attacker establishes an adjacent network position (T1557.002 ARP cache poisoning, T1557.003 DHCP spoofing, T1071.001 hostile proxy) on a path between the Automate agent and its server, or compromises a TLS-terminating middlebox.
2. Interception — Attacker observes the agent's periodic poll (default check-in interval ~60 seconds) to the Automate server endpoint, identifying plugin-pull or self-update requests.
3. Payload substitution — Attacker responds with a tampered DLL plugin or updater binary in place of the legitimate vendor payload (T1195.002 Compromise Software Supply Chain, T1574 Hijack Execution Flow).
4. Bypass of integrity check — Vulnerable agent code path either skips the integrity check entirely for the affected component class, accepts a forged or weak hash, or honors a server-supplied manifest the attacker controls.
5. Code execution — Agent loads the tampered DLL into LTSvc.exe or executes the updater under LocalSystem (T1129 Shared Modules; T1059 Command and Scripting Interpreter via plugin logic).
6. Persistence — Malicious payload installs as an LTSvc plugin, registers a scheduled task, creates a new Windows service, or modifies a Run key (T1543.003 Create or Modify System Process: Windows Service; T1547.001 Registry Run Keys).
7. Defense evasion — Plugin runs inside the trusted RMM process, evading EDR rules that allowlist LTSvc.exe activity (T1218 System Binary Proxy Execution, T1027 Obfuscated Files or Information).
8. Lateral movement and follow-on impact — Attacker pivots through the Automate management plane to push commands, scripts, or installers to other managed endpoints (T1021 Remote Services; T1072 Software Deployment Tools), enabling broad ransomware staging (T1486), credential theft (T1003), or data exfiltration (T1041).

## Affected Products

- ConnectWise Automate, all versions prior to 2026.5 (on-premise deployments).
- ConnectWise Automate Cloud — automatically patched by ConnectWise on or before 2026-05-21.

## Detection Considerations

No indicators of compromise have been published by ConnectWise as of the disclosure date. Defensive telemetry should focus on (a) unexpected child processes of LTSvc.exe, especially scripting hosts (powershell.exe, cmd.exe, wscript.exe, cscript.exe), (b) unsigned or anomalously signed DLLs in C:\Windows\LTSvc\Plugins\, (c) agent self-update events occurring outside change windows, (d) ARP/DHCP/DNS anomalies on networks hosting Automate-managed endpoints, and (e) TLS certificate mismatches on the agent-server channel where TLS interception is not authorized.

## Remediation

On-premise: upgrade ConnectWise Automate to 2026.5 within 30 days per the vendor priority-2 guidance. Cloud: no action required, already patched. Compensating controls until patched include enforcing strict network segmentation around RMM agents, validating that agent-server TLS chains are pinned to vendor CAs only, disabling TLS interception of RMM traffic, and increasing EDR sensitivity to LTSvc.exe child process anomalies.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
- T1199 Trusted Relationship
- T1190 Exploit Public-Facing Application
- T1557 Adversary-in-the-Middle
- T1557.002 Adversary-in-the-Middle: ARP Cache Poisoning
- T1557.003 Adversary-in-the-Middle: DHCP Spoofing
- T1129 Shared Modules
- T1059 Command and Scripting Interpreter
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1543.003 Create or Modify System Process: Windows Service
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1574 Hijack Execution Flow
- T1574.001 DLL
- T1553.002 Subvert Trust Controls: Code Signing
- T1218 System Binary Proxy Execution
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1071.001 Application Layer Protocol: Web Protocols
- T1105 Ingress Tool Transfer
- T1072 Software Deployment Tools
- T1021 Remote Services
- T1082 System Information Discovery
- T1005 Data from Local System
- T1486 Data Encrypted for Impact

## Sources

- [ConnectWise Automate 2026.5 Security Update (Vendor Bulletin)](https://www.connectwise.com/company/trust/security-bulletins/2026-05-21-connectwise-automate-bulletin)
- [NVD - CVE-2026-9089](https://nvd.nist.gov/vuln/detail/CVE-2026-9089)
- [ConnectWise Automate Vulnerability Let Attackers Bypass Security Checks](https://cybersecuritynews.com/connectwise-automate-vulnerability/)
- [CWE-494: Download of Code Without Integrity Check](https://cwe.mitre.org/data/definitions/494.html)
- [MITRE ATT&CK T1557 — Adversary-in-the-Middle](https://attack.mitre.org/techniques/T1557/)
- [MITRE ATT&CK T1195.002 — Compromise Software Supply Chain](https://attack.mitre.org/techniques/T1195/002/)
- [MITRE ATT&CK T1072 — Software Deployment Tools](https://attack.mitre.org/techniques/T1072/)
- [CVSS 3.1 Calculator for CVE-2026-9089](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0588
