logo

MOVEit Transfer Flaws Push Security Defense Into a Race With Attackers

ID: 2dc6292c-86f2-533b-8d91-7828168a40f1

STIX ID: report--2dc6292c-86f2-533b-8d91-7828168a40f1

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-06-27

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Progress Software disclosed critical authentication-bypass vulnerabilities in MOVEit Transfer and MOVEit Gateway (CVE-2024-5806, CVE-2024-5805). Patches are available but a public PoC, active scanning, and early exploit attempts (ShadowServer and Censys observations, ~2,700 exposed instances) increase the risk; organizations are urged to apply patches and additional mitigations (block public RDP, restrict outbound transfers) to reduce exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.