Briefing

Progress Software Issues Critical MOVEit Authentication Bypass

security
by [email protected] (The Hacker News) ·

Install the newest MOVEit Automation security patch to fix the authentication bypass and other critical flaws.

What to do now

Apply the latest MOVEit Automation security patch immediately.

Summary

Progress Software has released a critical security advisory for its MOVEit Automation platform, identifying a severe authentication bypass flaw (CVE‑2026‑4670) that affects all releases before 2025.1.5, 2025.0.9, and 2024.1.8. The vulnerability allows remote attackers to log in without valid credentials, enabling them to execute low‑complexity attacks that require no user interaction. The advisory also warns of a separate high‑severity privilege escalation issue (CVE‑2026‑5174) in the same product. Over 1,400 MOVEit Automation instances are publicly exposed online, including several U.S. government agencies, and the software is used by more than 3,000 enterprise organizations worldwide.

The only effective mitigation is to upgrade to the latest patched release, which will temporarily disrupt service during the maintenance window. Progress stresses that no configuration changes can remediate the flaw, and administrators must plan for a brief outage. The advisory echoes the 2023 MOVEit Transfer breach that compromised more than 2,100 organizations, underscoring the potential for data exfiltration and ransomware attacks. The company urges immediate action to protect sensitive data and prevent exploitation.

Organizations using MOVEit Automation are advised to act swiftly, verify their version, and apply the patch as soon as possible. Regular patch management and monitoring of Managed File Transfer (MFT) solutions are highlighted as essential defenses against similar vulnerabilities. The incident serves as a stark reminder of the importance of timely updates and vigilance in protecting critical infrastructure from evolving cyber threats.

Key changes

  • Progress released updates for MOVEit Automation to fix two critical flaws
  • One flaw allows authentication bypass
  • Second flaw could compromise data integrity during transfers
  • MOVEit Automation is a server‑based managed file transfer solution
  • No custom scripts required
  • Patch recommended for all users
  • Failure to update exposes sensitive data

Affects

enterprise internal

Source angles · 2 perspectives

The Hacker News
Independent angle

Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass

Open
Bleeping Computer
Independent angle

Progress warns of critical MOVEit Automation auth bypass flaw

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting