CVE-2026-4670: exploitation status and patch state
CVE-2026-4670 · CVSS 9.8 CRITICAL · EPSS 6%
Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass.
This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.
Is CVE-2026-4670 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 6%.
Public exploit code: none found in monitored sources.