Find notable cyber news and cases, enriched with sources, timelines, and signals.

Progress Software security patch release for CVE-2026-4670

Security Patch Release
First reported
Last updated
Happening score
H score 44
1 unique sources, 1 articles

Summary

Hide ▲

Progress Software has released MOVEit Automation updates to fix CVE-2026-4670 and CVE-2026-5174, including a critical authentication bypass that could expose enterprise file-transfer systems. The flaws affect MOVEit Automation <= 2025.1.4, <= 2025.0.8, and <= 2024.1.7, with fixed builds now available. Progress says the bugs could enable unauthorized access, administrative control, and data exposure through the service backend command port interfaces. There are no workarounds, so affected users need to install the patched releases quickly.

Related Happenings

Progress Software ShareFile Storage Zone Controller path traversal patch release

Security Patch Release
H score38 First: 14.07.2026 19:08 Last: 14.07.2026 19:08 Sources 1

About this happening: Progress Software released 5.12.5 and 6.0.2 for ShareFile Storage Zone Controller after a high-severity zero-day path traversal vulnerability forced last week’s sh...

Progress ShareFile Storage Zone Controllers shutdown guidance

Advisory/Mitigation
H score44 First: 10.07.2026 19:26 Last: 10.07.2026 19:26 Sources 1

About this happening: Progress Software has told ShareFile customers using Storage Zone Controllers to shut down their servers immediately after detecting a credible external security...

Latest development: 14.07.2026 19:08

Progress Software identified a high-severity path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller, reserved a CVE identifier for it, and released versions 5.12.5 and 6.0.2 to patch the flaw and restore the controllers after updating. The company said it has no indication of unauthorized access to any ShareFile customer account or data and no active threat has been identified.

Progress LoadMaster CVE-2026-8037 patch release

Security Patch Release
H score52 First: 30.06.2026 10:38 Last: 30.06.2026 10:38 Sources 1

About this happening: Progress published fixed LoadMaster versions for CVE-2026-8037, closing a pre-auth root command execution path on appliances with the API enabled. Administrators r...

Veeam security patch release for CVE-2026-44963

Security Patch Release
H score79 First: 09.06.2026 17:27 Last: 09.06.2026 17:27 Sources 1

About this happening: Veeam released security updates for Veeam Backup & Replication to fix CVE-2026-44963, a critical flaw that could enable remote code execution on domain-joined ba...

Ivanti security patch release for CVE-2026-8043

Security Patch Release
H score25 First: 18.05.2026 13:54 Last: 18.05.2026 13:54 Sources 1

About this happening: Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...

Timeline

  1. 04.05.2026 19:34 2 articles · 2mo ago

    Progress Software patches MOVEit Automation authentication bypass

    Mitigation Patch Update

    Progress Software released updates for MOVEit Automation to fix CVE-2026-4670 and CVE-2026-5174, including a critical authentication bypass and an improper input validation flaw that could enable privilege escalation. Progress said exploitation could lead to unauthorized access, administrative control, and data exposure through the service backend command port interfaces, and that no workaround resolves the issues. The affected releases were MOVEit Automation <= 2025.1.4, <= 2025.0.8, and <= 2024.1.7, with fixed builds 2025.1.5, 2025.0.9, and 2024.1.8 available. Airbus SecLab researchers Anaïs Gantet, Delphine Gourdou, Quentin Liddell, and Matteo Ricordeau were credited with discovering and reporting the two vulnerabilities.

    Show sources