logo

MOVEit automation flaws could enable full system compromise

ID: 6513ffaf-5e77-5705-8cdc-71b6493b209a

STIX ID: report--6513ffaf-5e77-5705-8cdc-71b6493b209a

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Pierluigi Paganini

...
...

Progress Software fixed two serious vulnerabilities in MOVEit Automation — CVE-2026-4670 (authentication bypass) and CVE-2026-5174 (privilege escalation) — that affect multiple supported versions and could allow unauthorized access, privilege elevation, administrative control, and data exposure. The advisory, based on research from Airbus SecLab, reports no available workarounds and warns these flaws can be rapidly weaponized at scale, citing the 2023 Cl0p campaign against MOVEit as an example of the potential impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.