logo

Critical MOVEit Vulnerabilities Enables Authentication Bypass

ID: 79283832-7388-5417-9b6e-18be8444486a

STIX ID: report--79283832-7388-5417-9b6e-18be8444486a

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Abinaya

...
...

Progress Software issued a critical advisory for MOVEit Automation describing two severe flaws discovered by Airbus SecLab that allow unauthenticated attackers to bypass authentication (CVE-2026-4670) and escalate privileges (CVE-2026-5174) via the service backend command port, potentially leading to full administrative control and data theft; Progress has released patched builds (2025.1.5, 2025.0.9, 2024.1.8) and urges administrators to apply full-install updates and check affected versions in the Web Admin dashboard.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.