MOVEit Automation is not a routine patch job. The flaw lets remote attackers bypass authentication on a central file-transfer orchestrator, and Progress says the only fix is a full-installer upgrade that takes the system down during remediation.
Progress says CVE-2026-4670 affects MOVEit Automation before 2025.1.5, 2025.0.9, and 2024.1.8. The company recommends upgrading to the latest version, and says there is no hotfix path; the patched release must be installed with the full installer. BleepingComputer also cites more than 1,400 exposed instances online, including systems tied to U.S. local and state government agencies.
The operational risk is delay. Teams that need a maintenance window to fix an auth bypass may leave exposed transfer systems online longer than they want, and MOVEit’s history makes this class of flaw hard to dismiss as theoretical.