Find notable cyber news and cases, enriched with sources, timelines, and signals.

MOVEit Automation authentication bypass (CVE-2026-4670)

Vulnerability
First reported
Last updated
Happening score
H score 69
2 unique sources, 2 articles

Summary

Hide ▲

A critical authentication bypass in MOVEit Automation affects versions before 2025.1.5, 2025.0.9, and 2024.1.8, creating remote access risk for exposed file-transfer systems. Progress Software says the only remediation is to upgrade to a patched release using the full installer, and the upgrade causes a temporary system outage. The flaw is tracked as CVE-2026-4670 and can be exploited without privileges or user interaction.

Related Happenings

ShareFile Storage Zone Controller path traversal zero-day path traversal flaw

Vulnerability
H score1 First: 14.07.2026 19:08 Last: 14.07.2026 19:08 Sources 1

About this happening: Progress confirmed a high-severity path traversal zero-day in ShareFile Storage Zone Controller, exposing all 5.x and 6.x versions to arbitrary file read and write ris...

Progress ShareFile Storage Zone Controllers shutdown guidance

Advisory/Mitigation
H score44 First: 10.07.2026 19:26 Last: 10.07.2026 19:26 Sources 1

About this happening: Progress Software has told ShareFile customers using Storage Zone Controllers to shut down their servers immediately after detecting a credible external security...

Latest development: 14.07.2026 19:08

Progress Software identified a high-severity path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller, reserved a CVE identifier for it, and released versions 5.12.5 and 6.0.2 to patch the flaw and restore the controllers after updating. The company said it has no indication of unauthorized access to any ShareFile customer account or data and no active threat has been identified.

Linux distributions mitigation advisories for CVE-2026-31431

Advisory/Mitigation
H score39 First: 30.04.2026 12:24 Last: 30.04.2026 12:24 Sources 1

About this happening: Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...

CISA orders FCEB remediation for CVE-2025-60710

Public Sector Action
H score34 First: 15.04.2026 17:51 Last: 15.04.2026 17:51 Sources 1

About this happening: CISA added CVE-2025-60710 to its actively exploited catalog and gave FCEB agencies two weeks to secure systems under BOD 22-01. The move targets a Windows Ta...

CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551

Public Sector Action
H score53 First: 04.02.2026 07:50 Last: 04.02.2026 07:50 Sources 1

About this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...

Timeline

  1. 04.05.2026 15:18 3 articles · 2mo ago

    Progress warns MOVEit Automation customers to patch CVE-2026-4670

    Mitigation Patch Update

    Progress Software warns customers to patch a critical authentication bypass in MOVEit Automation, tracked as CVE-2026-4670 and affecting versions before 2025.1.5, 2025.0.9, and 2024.1.8; the company says upgrading to a patched release with the full installer is the only way to remediate the issue, and the upgrade causes a system outage while it runs.

    Show sources
  2. 04.05.2026 15:18 3 articles · 2mo ago

    Progress warns MOVEit Automation customers to patch CVE-2026-4670

    Mitigation Patch Update

    Progress Software warns customers to patch a critical authentication bypass in MOVEit Automation, tracked as CVE-2026-4670 and affecting versions before 2025.1.5, 2025.0.9, and 2024.1.8; the company says upgrading to a patched release with the full installer is the only way to remediate the issue, and the upgrade causes a system outage while it runs.

    Show sources