Progress patches critical vulnerabilities in MOVEit Automation

TL;DR AI
2 min readKey summary
Progress has patched two critical MOVEit Automation vulnerabilities: a CVSS 9.8 authentication bypass and a CVSS 7.7 privilege escalation flaw.
The only remediation is to upgrade to the fixed releases; no active exploitation has been confirmed so far.
The bugs could let attackers move from unauthenticated access to full administrative control on internet-exposed file transfer systems.
Affected issues are tracked as CVE-2026-4670 and CVE-2026-5174, underscoring the need for immediate software updates.



