logo

MOVEit Automation Alert: Critical Authentication Bypass Hits CVSS 9.8

ID: bb92ca6a-98d3-5d06-9a3f-c1399893da44

STIX ID: report--bb92ca6a-98d3-5d06-9a3f-c1399893da44

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Ddos

...
...

Progress Software issued an urgent advisory for MOVEit Automation describing two vulnerabilities that could allow administrative takeover: CVE-2026-4670 (critical authentication bypass, CVSS 9.8) and CVE-2026-5174 (privilege escalation, CVSS 7.7). The flaws affect multiple releases (including versions prior to 2024.0.0); administrators are instructed to verify versions, apply the full-installer patches (which may require scheduled downtime), and monitor audit logs for unauthorized access or privilege escalations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.