logo

Warning: Critical authentication bypass in MOVEit Automation (CVE-2026-4670), Patch Immediately!

ID: fccb5924-d836-5b7e-a359-bde883aad889

STIX ID: report--fccb5924-d836-5b7e-a359-bde883aad889

Feed Name: CCB Advisories Feed

Threat Score
80/100

Date Published: 2026-05-04

Date Updated: 2026-07-24

...
...

Progress MOVEit Automation is affected by two vulnerabilities—a critical authentication bypass (CVE-2026-4670, CVSS 9.8) and a high-severity improper input validation leading to privilege escalation (CVE-2026-5174, CVSS 7.7)—impacting multiple product branches; the Centre for Cybersecurity Belgium and the vendor recommend immediate patching to specified versions (MOVEit Automation 2025.1.5 / 2025.0.9 / 2024.1.8 or later) and increased monitoring, noting no confirmed active exploitation but elevated risk due to historical targeting of managed file transfer solutions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.