CVE-2026-4670
CVSS 9.8 CRITICAL: authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication… EPSS 6% (92nd percentile), up from 0.2%.
Vulnerabilities · 133 days ago
MOVEit Automation is not a routine patch job. The flaw lets remote attackers bypass authentication on a central file-transfer orchestrator, and Progress says the only fix is a full-installer upgrade that takes the system down during remediation.
Progress says CVE-2026-4670 affects MOVEit Automation before 2025.1.5, 2025.0.9, and 2024.1.8. The company recommends upgrading to the latest version, and says there is no hotfix path; the patched release must be installed with the full installer. BleepingComputer also cites more than 1,400 exposed instances online, including systems tied to U.S. local and state government agencies.
The operational risk is delay. Teams that need a maintenance window to fix an auth bypass may leave exposed transfer systems online longer than they want, and MOVEit’s history makes this class of flaw hard to dismiss as theoretical.
CVSS 9.8 CRITICAL: authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication… EPSS 6% (92nd percentile), up from 0.2%.
4 sources covering this story
Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass
MOVEit Automation flaws (CVE-2026-4670, CVE-2026-5174) enable bypass and escalation, risking enterprise data exposure.
Critical MOVEit Automation auth bypass vulnerability fixed (CVE-2026-4670) - Help Net Security
CVE-2026-4670 and CVE-2026-5174 in MOVEit Automation may allow unauthorized access, administrative control, and lead to data exposure.
New MOVEit vulnerabilities prompt urgent patch warning
Progress Software warned customers to immediately upgrade the file-transfer tool to fix the serious flaws.
Progress warns of critical MOVEit Automation auth bypass flaw
Progress Software warned customers to patch a critical authentication bypass vulnerability in its MOVEit Automation enterprise-grade managed file transfer (MFT) application.
Part of the PlainSec briefing for 2026-05-05