Progress Software issues security guidance and releases updates for MOVEit Automation, an enterprise managed file transfer (MFT) product used to automate and schedule file movement workflows. Multiple outlets report that Progress addresses two vulnerabilities in MOVEit Automation. One flaw enables a critical authentication bypass, meaning an attacker could potentially access the application without proper authentication. The second flaw involves privilege escalation, which could allow an attacker to gain administrative-level control. Help Net Security identifies the issues as CVE-2026-4670 (authentication bypass) and CVE-2026-5174 (privilege escalation). The same source says researchers at Airbus privately reported the vulnerabilities to Progress. None of the provided summaries indicate that the flaws are being exploited in the wild at the time of reporting, but they emphasize that organizations should apply the vendor’s updates or upgrade to fixed versions. Overall, the coverage aligns on the type of defects (authentication bypass and privilege escalation), the affected product (MOVEit Automation), and the recommended mitigation (patch immediately using Progress’s releases).
Progress patches critical authentication bypass and privilege escalation flaws in MOVEit Automation
Progress Software issues security guidance and releases updates for MOVEit Automation, an enterprise managed file transfer (MFT) product used to automate and schedule file movement workflows. Multiple...
- Progress Software releases updates for MOVEit Automation to address security vulnerabilities.
- A critical authentication bypass flaw is tracked as CVE-2026-4670.
- A privilege escalation flaw is tracked as CVE-2026-5174.
- The vulnerabilities were privately reported by Airbus researchers, according to Help Net Security.
- All sources advise upgrading to fixed versions to mitigate the risk.
Progress Software has released updates to address two security flaws in MOVEit Automation, including a critical bug that could result in an authentication bypass. MOVEit Automation (formerly Central) is a secure, server-based managed file transfer (MFT) solution used to schedule and automate file movement workflows in enterprise environments without requiring any custom scripts. The
3 months agoProgress Software has fixed a critical authentication bypass (CVE-2026-4670) and a privilege escalation (CVE-2026-5174) vulnerability in MOVEit Automation, exploitation of which “may lead to unauthorized access, administrative control, and data exposure.” The vulnerabilities were reported privately by Airbus researchers and there’s no mention of them being leveraged by attackers in the wild. Still, performing an upgrade to a fixed version is “strongly” advised. CVE-2026-4670 and CVE-2026-5174 Progress Software’s MOVEit Transfer, an enterprise managed file transfer … More → The post Critical MOVEit Automation auth bypass vulnerability fixed (CVE-2026-4670) appeared first on Help Net Security.
3 months agoProgress Software warned customers to patch a critical authentication bypass vulnerability in its MOVEit Automation enterprise-grade managed file transfer (MFT) application. [...]
3 months ago
Alpine confirms Franco Colapinto contract extension for 2027 alongside Pierre Gasly
Alpine confirms it will keep Formula 1 driver Franco Colapinto for the 2027 season, retaining the same line-up that incl...
NRL to make rule exception for Jai Arrow to reach 100 Rabbitohs games
South Sydney Rabbitohs winger Jai Arrow is set to reach his 100th NRL appearance for the club after the NRL agrees to a...
Muchova and Mensik win US Open mixed doubles title and $1m prize
Karolina Muchova and Jakub Mensik win the US Open mixed doubles championship, beating Belinda Bencic and Flavio Cobolli...