Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass
ID: cb8cc497-7b60-5f3f-8a02-54556988651c
STIX ID: report--cb8cc497-7b60-5f3f-8a02-54556988651c
Feed Name: The Hacker News
Progress Software released updates for MOVEit Automation to address two critical vulnerabilities — CVE-2026-4670 (authentication bypass, CVSS 9.8) and CVE-2026-5174 (improper input validation, CVSS 7.7) — affecting multiple older releases (fixed in 2025.1.5, 2025.0.9, and 2024.1.8); Airbus SecLab researchers are credited, no workarounds exist, and Progress reports no known exploitation in the wild but urges prompt patching to prevent unauthorized access, privilege escalation, and data exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
