Connectwise is urging customers to update their ScreenConnect, Automate, and ConnectWise RMM solutions by June 13, following the rotation of digital code signing certificates. The initial warning indicated that the certificate changes would take effect on June 10, but this was later extended to June 13. The flagged vulnerability relates to how ScreenConnect managed configuration data in earlier versions, prompting Connectwise to enhance its software’s security measures.
This action is intended to address concerns raised by a third-party researcher regarding the handling of configuration data in earlier versions of ScreenConnect and is not linked to a recent nation-state attack disclosed by the company. The planned rotation follows a recent disclosure that ConnectWise detected malicious activity in its environment, although the company emphasized that the certificate rotation is a separate measure. Customers with on-premises versions of ScreenConnect or Automate are advised to update their software and validate that all agents are updated by 8 PM Eastern Time on Friday to prevent disruptions. ConnectWise is also automatically updating certificates and agents for its cloud instances.
Why do we care?
ConnectWise wants to distance this from the nation-state breach it previously disclosed—but customers don’t experience these events in isolation. A security incident combined with a rushed certificate rotation and vague language regarding configuration flaws results in reduced confidence in the vendor’s internal controls.
Let’s not forget: ScreenConnect was already the target of mass exploitation earlier this year. That breach cycle remains fresh in the minds of MSPs—and clients.
There’s a counter-argument: digital certificate rotation is a best practice, and ConnectWise may simply be enhancing its hygiene in response to recent scrutiny. Proactive maintenance isn’t inherently suspicious.
But if that’s true, why the hard deadline? Why not a phased rotation with an optional fallback? The aggressive timeline implies there’s more beneath the surface.
This isn’t just a certificate update—it’s a stress test for MSPs still using ConnectWise’s legacy tools, particularly those on-prem. It raises critical takeaways:
Every RMM and remote tool vendor is now part of the threat surface. Certificate integrity, update discipline, and rapid response are more important than ever.
MSPs should regard certificate-related updates as critical infrastructure changes, not secondary patches.
Vendors need to be more transparent about what prompted certificate rotations, especially when they follow breaches. Obfuscation undermines partner trust.
Bottom line: MSPs must audit and test their agent update processes now. If this incident doesn’t spark a broader conversation about vendor risk management, it should—because the ability to trust your RMM is not optional.

