Switch language한국어
Back to the list

Progress patches critical vulnerabilities in MOVEit Automation

TL;DR AI

Key summary

2 min read
  1. Progress has patched two critical MOVEit Automation vulnerabilities: a CVSS 9.8 authentication bypass and a CVSS 7.7 privilege escalation flaw.

  2. The only remediation is to upgrade to the fixed releases; no active exploitation has been confirmed so far.

  3. The bugs could let attackers move from unauthenticated access to full administrative control on internet-exposed file transfer systems.

  4. Affected issues are tracked as CVE-2026-4670 and CVE-2026-5174, underscoring the need for immediate software updates.

Read the original