CVE-2026-4670
CVSS 9.8 CRITICAL: authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication… EPSS 6% (92nd percentile), up from 0.2%.
Vulnerabilities & Exploits
MOVEit Automation is not a routine patch job. The flaw lets remote attackers bypass authentication on a central file-transfer orchestrator, and Progress says the only fix is a full-installer upgrade that takes the system down during remediation.
Progress says CVE-2026-4670 affects MOVEit Automation before 2025.1.5, 2025.0.9, and 2024.1.8. The company recommends upgrading to the latest version, and says there is no hotfix path; the patched release must be installed with the full installer. BleepingComputer also cites more than 1,400 exposed instances online, including systems tied to U.S. local and state government agencies.
The operational risk is delay. Teams that need a maintenance window to fix an auth bypass may leave exposed transfer systems online longer than they want, and MOVEit’s history makes this class of flaw hard to dismiss as theoretical.
4 sources · May 5
CVSS 9.8 CRITICAL: authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication… EPSS 6% (92nd percentile), up from 0.2%.
The Hacker News
Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass
MOVEit Automation flaws (CVE-2026-4670, CVE-2026-5174) enable bypass and escalation, risking enterprise data exposure.
originalHelp Net Security
Critical MOVEit Automation auth bypass vulnerability fixed (CVE-2026-4670) - Help Net Security
CVE-2026-4670 and CVE-2026-5174 in MOVEit Automation may allow unauthorized access, administrative control, and lead to data exposure.
originalCybersecurity Dive
New MOVEit vulnerabilities prompt urgent patch warning
Progress Software warned customers to immediately upgrade the file-transfer tool to fix the serious flaws.
originalPart of the PlainSec briefing for 2026-05-04
Every edition of this story: MOVEit Automation Auth Bypass Forces Full-Installer Upgrades