Progress Software security patch release for CVE-2026-4670
Security Patch Release
Summary
Hide ▲
Show ▼
Progress Software has released MOVEit Automation updates to fix CVE-2026-4670 and CVE-2026-5174, including a critical authentication bypass that could expose enterprise file-transfer systems. The flaws affect MOVEit Automation <= 2025.1.4, <= 2025.0.8, and <= 2024.1.7, with fixed builds now available. Progress says the bugs could enable unauthorized access, administrative control, and data exposure through the service backend command port interfaces. There are no workarounds, so affected users need to install the patched releases quickly.
Related Happenings
Progress Software ShareFile Storage Zone Controller path traversal patch release
Security Patch Release
H score38
First: 14.07.2026 19:08
Last: 14.07.2026 19:08
Sources 1
About this happening:
Progress Software released 5.12.5 and 6.0.2 for ShareFile Storage Zone Controller after a high-severity zero-day path traversal vulnerability forced last week’s sh...
Progress Software ShareFile Storage Zone Controller path traversal patch release
Security Patch ReleaseAbout this happening: Progress Software released 5.12.5 and 6.0.2 for ShareFile Storage Zone Controller after a high-severity zero-day path traversal vulnerability forced last week’s sh...
Progress ShareFile Storage Zone Controllers shutdown guidance
Advisory/Mitigation
H score44
First: 10.07.2026 19:26
Last: 10.07.2026 19:26
Sources 1
About this happening:
Progress Software has told ShareFile customers using Storage Zone Controllers to shut down their servers immediately after detecting a credible external security...
Progress ShareFile Storage Zone Controllers shutdown guidance
Advisory/MitigationAbout this happening: Progress Software has told ShareFile customers using Storage Zone Controllers to shut down their servers immediately after detecting a credible external security...
Latest development: 14.07.2026 19:08
Progress Software identified a high-severity path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller, reserved a CVE identifier for it, and released versions 5.12.5 and 6.0.2 to patch the flaw and restore the controllers after updating. The company said it has no indication of unauthorized access to any ShareFile customer account or data and no active threat has been identified.
Progress LoadMaster CVE-2026-8037 patch release
Security Patch Release
H score52
First: 30.06.2026 10:38
Last: 30.06.2026 10:38
Sources 1
About this happening:
Progress published fixed LoadMaster versions for CVE-2026-8037, closing a pre-auth root command execution path on appliances with the API enabled. Administrators r...
Progress LoadMaster CVE-2026-8037 patch release
Security Patch ReleaseAbout this happening: Progress published fixed LoadMaster versions for CVE-2026-8037, closing a pre-auth root command execution path on appliances with the API enabled. Administrators r...
Veeam security patch release for CVE-2026-44963
Security Patch Release
H score79
First: 09.06.2026 17:27
Last: 09.06.2026 17:27
Sources 1
About this happening:
Veeam released security updates for Veeam Backup & Replication to fix CVE-2026-44963, a critical flaw that could enable remote code execution on domain-joined ba...
Veeam security patch release for CVE-2026-44963
Security Patch ReleaseAbout this happening: Veeam released security updates for Veeam Backup & Replication to fix CVE-2026-44963, a critical flaw that could enable remote code execution on domain-joined ba...
Ivanti security patch release for CVE-2026-8043
Security Patch Release
H score25
First: 18.05.2026 13:54
Last: 18.05.2026 13:54
Sources 1
About this happening:
Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Ivanti security patch release for CVE-2026-8043
Security Patch ReleaseAbout this happening: Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Timeline
-
04.05.2026 19:34 2 articles · 2mo ago
Progress Software patches MOVEit Automation authentication bypass
Mitigation Patch UpdateProgress Software released updates for MOVEit Automation to fix CVE-2026-4670 and CVE-2026-5174, including a critical authentication bypass and an improper input validation flaw that could enable privilege escalation. Progress said exploitation could lead to unauthorized access, administrative control, and data exposure through the service backend command port interfaces, and that no workaround resolves the issues. The affected releases were MOVEit Automation <= 2025.1.4, <= 2025.0.8, and <= 2024.1.7, with fixed builds 2025.1.5, 2025.0.9, and 2024.1.8 available. Airbus SecLab researchers Anaïs Gantet, Delphine Gourdou, Quentin Liddell, and Matteo Ricordeau were credited with discovering and reporting the two vulnerabilities.
Show sources
- Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass — thehackernews.com — 04.05.2026 19:34
- Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass — thehackernews.com — 04.05.2026 19:34