Progress warns of critical MOVEit Automation auth bypass flaw
ID: 9d171d6d-1ab1-59de-b961-00ac35a2f0c0
STIX ID: report--9d171d6d-1ab1-59de-b961-00ac35a2f0c0
Feed Name: Bleeping Computer
Progress Software released patches for a critical authentication-bypass vulnerability (CVE-2026-4670) and a high-severity privilege escalation (CVE-2026-5174) in MOVEit Automation; the flaws allow unauthenticated remote attacks of low complexity and require upgrading to patched releases to remediate. A Shodan scan found over 1,400 exposed MOVEit Automation instances, some tied to U.S. local/state agencies, increasing the potential impact, though the vendor has not reported confirmed in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
