Progress Patches Critical MOVEit Automation Flaws

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Progress Software released updates for MOVEit Automation addressing CVE-2026-4670, a CVSS 9.8 authentication bypass, and CVE-2026-5174, a CVSS 7.7 improper input validation flaw enabling privilege escalation.
- The flaws affect versions ≤2025.1.4, ≤2025.0.8, and ≤2024.1.7, with fixes shipped in 2025.1.5, 2025.0.9, and 2024.1.8 respectively.
- Airbus SecLab researchers Anaïs Gantet, Delphine Gourdou, Quentin Liddell, and Matteo Ricordeau discovered and reported both vulnerabilities.
- Progress warned exploitation of the service backend command port interfaces could lead to unauthorized access, administrative control, and data exposure.
- No workarounds exist, and Progress makes no mention of in-the-wild exploitation, though the advisory urges prompt patching given that prior MOVEit Transfer flaws have been weaponized by ransomware gangs like Cl0p.
Why it matters: MOVEit Automation is an enterprise managed file transfer tool, so a CVSS 9.8 auth bypass with no workaround puts organizations running unpatched versions at immediate risk of full administrative takeover and data exposure — a scenario Cl0p previously exploited against MOVEit Transfer.




