MOVEit Automation authentication bypass (CVE-2026-4670)
Vulnerability
Summary
Hide ▲
Show ▼
A critical authentication bypass in MOVEit Automation affects versions before 2025.1.5, 2025.0.9, and 2024.1.8, creating remote access risk for exposed file-transfer systems. Progress Software says the only remediation is to upgrade to a patched release using the full installer, and the upgrade causes a temporary system outage. The flaw is tracked as CVE-2026-4670 and can be exploited without privileges or user interaction.
Related Happenings
ShareFile Storage Zone Controller path traversal zero-day path traversal flaw
Vulnerability
H score1
First: 14.07.2026 19:08
Last: 14.07.2026 19:08
Sources 1
About this happening:
Progress confirmed a high-severity path traversal zero-day in ShareFile Storage Zone Controller, exposing all 5.x and 6.x versions to arbitrary file read and write ris...
ShareFile Storage Zone Controller path traversal zero-day path traversal flaw
VulnerabilityAbout this happening: Progress confirmed a high-severity path traversal zero-day in ShareFile Storage Zone Controller, exposing all 5.x and 6.x versions to arbitrary file read and write ris...
Progress ShareFile Storage Zone Controllers shutdown guidance
Advisory/Mitigation
H score44
First: 10.07.2026 19:26
Last: 10.07.2026 19:26
Sources 1
About this happening:
Progress Software has told ShareFile customers using Storage Zone Controllers to shut down their servers immediately after detecting a credible external security...
Progress ShareFile Storage Zone Controllers shutdown guidance
Advisory/MitigationAbout this happening: Progress Software has told ShareFile customers using Storage Zone Controllers to shut down their servers immediately after detecting a credible external security...
Latest development: 14.07.2026 19:08
Progress Software identified a high-severity path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller, reserved a CVE identifier for it, and released versions 5.12.5 and 6.0.2 to patch the flaw and restore the controllers after updating. The company said it has no indication of unauthorized access to any ShareFile customer account or data and no active threat has been identified.
Linux distributions mitigation advisories for CVE-2026-31431
Advisory/Mitigation
H score39
First: 30.04.2026 12:24
Last: 30.04.2026 12:24
Sources 1
About this happening:
Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...
Linux distributions mitigation advisories for CVE-2026-31431
Advisory/MitigationAbout this happening: Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...
CISA orders FCEB remediation for CVE-2025-60710
Public Sector Action
H score34
First: 15.04.2026 17:51
Last: 15.04.2026 17:51
Sources 1
About this happening:
CISA added CVE-2025-60710 to its actively exploited catalog and gave FCEB agencies two weeks to secure systems under BOD 22-01. The move targets a Windows Ta...
CISA orders FCEB remediation for CVE-2025-60710
Public Sector ActionAbout this happening: CISA added CVE-2025-60710 to its actively exploited catalog and gave FCEB agencies two weeks to secure systems under BOD 22-01. The move targets a Windows Ta...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector Action
H score53
First: 04.02.2026 07:50
Last: 04.02.2026 07:50
Sources 1
About this happening:
CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector ActionAbout this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
Timeline
-
04.05.2026 15:18 3 articles · 2mo ago
Progress warns MOVEit Automation customers to patch CVE-2026-4670
Mitigation Patch UpdateProgress Software warns customers to patch a critical authentication bypass in MOVEit Automation, tracked as CVE-2026-4670 and affecting versions before 2025.1.5, 2025.0.9, and 2024.1.8; the company says upgrading to a patched release with the full installer is the only way to remediate the issue, and the upgrade causes a system outage while it runs.
Show sources
- Progress warns of critical MOVEit Automation auth bypass flaw — www.bleepingcomputer.com — 04.05.2026 15:18
- Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass — thehackernews.com — 04.05.2026 19:34
- Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass — thehackernews.com — 04.05.2026 19:34
-
04.05.2026 15:18 3 articles · 2mo ago
Progress warns MOVEit Automation customers to patch CVE-2026-4670
Mitigation Patch UpdateProgress Software warns customers to patch a critical authentication bypass in MOVEit Automation, tracked as CVE-2026-4670 and affecting versions before 2025.1.5, 2025.0.9, and 2024.1.8; the company says upgrading to a patched release with the full installer is the only way to remediate the issue, and the upgrade causes a system outage while it runs.
Show sources
- Progress warns of critical MOVEit Automation auth bypass flaw — www.bleepingcomputer.com — 04.05.2026 15:18
- Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass — thehackernews.com — 04.05.2026 19:34
- Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass — thehackernews.com — 04.05.2026 19:34