logo

MOVEit Transfer: Auth bypass and a look at exposure

ID: 993e1867-83db-5966-92d2-580df838b7bd

STIX ID: report--993e1867-83db-5966-92d2-580df838b7bd

Feed Name: Censys Blog

Threat Score
78/100

Date Published: 2024-06-26

Date Updated: 2026-04-27

Author: Ivonne Francia; The Censys Research Team

...
...

**Executive Summary:** Progress Software disclosed two authentication-bypass vulnerabilities in MOVEit Transfer and Gateway (CVE-2024-5806 and CVE-2024-5805), one of which received a CVSS score of 9.1; Censys observed ~2,700 publicly reachable MOVEit instances (primarily in the US) and published dashboards to track exposure, noting similarity to the 2023 exposure footprint and reminding organizations of the significant risk given prior mass exploitation by the Clop ransomware gang.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.