Progress Software issues security guidance and releases updates for MOVEit Automation, an enterprise managed file transfer (MFT) product used to automate and schedule file movement workflows. Multiple outlets report that Progress addresses two vulnerabilities in MOVEit Automation. One flaw enables a critical authentication bypass, meaning an attacker could potentially access the application without proper authentication. The second flaw involves privilege escalation, which could allow an attacker to gain administrative-level control. Help Net Security identifies the issues as CVE-2026-4670 (authentication bypass) and CVE-2026-5174 (privilege escalation). The same source says researchers at Airbus privately reported the vulnerabilities to Progress. None of the provided summaries indicate that the flaws are being exploited in the wild at the time of reporting, but they emphasize that organizations should apply the vendor’s updates or upgrade to fixed versions. Overall, the coverage aligns on the type of defects (authentication bypass and privilege escalation), the affected product (MOVEit Automation), and the recommended mitigation (patch immediately using Progress’s releases).