Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass

The Hacker News by The Hacker News
May 4, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananMay 04, 2026Vulnerability / Enterprise Software

Progress Software has released updates to address two security flaws in MOVEit Automation, including a critical bug that could result in an authentication bypass.

MOVEit Automation (formerly Central) is a secure, server-based managed file transfer (MFT) solution used to schedule and automate file movement workflows in enterprise environments without requiring any custom scripts. 

The vulnerabilities in question are CVE-2026-4670 (CVSS score: 9.8), an authentication bypass vulnerability, and CVE-2026-5174 (CVSS score: 7.7), an improper input validation vulnerability that could allow privilege escalation.

“Critical and high vulnerabilities in MOVEit Automation may allow authentication bypass and privilege escalation through the service backend command port interfaces,” Progress Software said in an advisory. “Exploitation may lead to unauthorized access, administrative control, and data exposure.”

The shortcomings affect the following versions –

  • MOVEit Automation <= 2025.1.4 (Fixed in MOVEit Automation 2025.1.5)
  • MOVEit Automation <= 2025.0.8 (Fixed in MOVEit Automation 2025.0.9)
  • MOVEit Automation <= 2024.1.7 (Fixed in MOVEit Automation 2024.1.8)

Airbus SecLab researchers Anaïs Gantet, Delphine Gourdou, Quentin Liddell, and Matteo Ricordeau have been credited with discovering and reporting the two vulnerabilities. There are no workarounds that resolve the issues.

While Progress makes no mention of the flaws being exploited in the wild, it’s essential that users apply the fixes as soon as possible for optimal protection, particularly given that prior flaws in MOVEit Transfer have been exploited by ransomware gangs like Cl0p.



Source link

The Hacker News

The Hacker News

Next Post
Traffic in the Strait of Hormuz won’t return to normal until August or later, according to Kalshi traders

Traffic in the Strait of Hormuz won’t return to normal until August or later, according to Kalshi traders

Recommended.

Infosys and International Tennis Hall of Fame Renew Collaboration until 2028, Harnessing AI to Revolutionize Tennis

Infosys and International Tennis Hall of Fame Renew Collaboration until 2028, Harnessing AI to Revolutionize Tennis

May 7, 2025
Stocks making the biggest moves midday: Nucor, Sunrun, Affirm, Zoetis, Circle and more

Stocks making the biggest moves midday: Nucor, Sunrun, Affirm, Zoetis, Circle and more

June 18, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio