Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical MOVEit Automation Flaw Patches Released by Progress

Critical MOVEit Automation Flaw Patches Released by Progress

Posted on May 4, 2026 By CWS

Progress Software has announced the release of security updates aimed at addressing significant vulnerabilities in its MOVEit Automation software. The updates are designed to fix two key issues, including a critical flaw that could potentially allow unauthorized access through an authentication bypass.

Understanding MOVEit Automation

MOVEit Automation, previously known as Central, is a secure solution for managing file transfers within enterprise environments. It facilitates the scheduling and automation of file movement tasks without necessitating custom scripts. This feature makes it a valuable tool for businesses seeking to streamline their file management processes effectively.

Details of the Security Vulnerabilities

The critical vulnerabilities identified are CVE-2026-4670, which has a CVSS score of 9.8 and involves authentication bypass, and CVE-2026-5174, with a CVSS score of 7.7, linked to improper input validation that may lead to privilege escalation. These flaws could be exploited to gain unauthorized access and control over the system, posing significant security risks.

Progress Software has highlighted the potential outcomes of these vulnerabilities, stating that they could allow unauthorized access, administrative privileges, and potential data exposure. The vulnerabilities impact several MOVEit Automation versions, specifically versions 2025.1.4 and earlier, 2025.0.8 and earlier, and 2024.1.7 and earlier.

Immediate Actions for Users

Researchers from Airbus SecLab, Anaïs Gantet, Delphine Gourdou, Quentin Liddell, and Matteo Ricordeau, were instrumental in discovering these vulnerabilities. While there are currently no known workarounds, Progress emphasizes the importance of applying the provided patches promptly to ensure system security.

Although there is no current evidence of these particular vulnerabilities being exploited in the wild, the history of similar issues in MOVEit Transfer being targeted by groups like Cl0p ransomware highlights the urgency for users to update their systems. Ensuring these updates are applied can significantly enhance protection against potential security threats.

Overall, these updates underscore the critical importance of maintaining up-to-date software to safeguard enterprise environments from emerging security threats. Users are urged to implement the updates immediately to mitigate any potential risks associated with these vulnerabilities.

The Hacker News Tags:authentication bypass, CVE-2026-4670, CVE-2026-5174, enterprise software, file transfer security, MOVEit Automation, Progress Software, ransomware protection, security update, vulnerability patch

Post navigation

Previous Post: Bluekit Phishing Kit Revolutionizes Cyber Attacks
Next Post: Trellix Investigates Source Code Repository Breach

Related Posts

Critical Linux Kernel Bug Allows Unauthorized Root Access Critical Linux Kernel Bug Allows Unauthorized Root Access The Hacker News
Mastra npm Packages Compromised in Supply Chain Attack Mastra npm Packages Compromised in Supply Chain Attack The Hacker News
New Malware SharkLoader Deploys Cobalt Strike New Malware SharkLoader Deploys Cobalt Strike The Hacker News
INTERPOL Dismantles Sniper Dz Phishing Platform INTERPOL Dismantles Sniper Dz Phishing Platform The Hacker News
Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns The Hacker News
Webinar Reveals Strategies Against Stealth Cyber Breaches Webinar Reveals Strategies Against Stealth Cyber Breaches The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Settra Ransomware Threatens Windows Networks
  • WordPress Patch Addresses Click2Shell Vulnerability
  • Feral Wolf Ransomware Exploits Exposed Business Systems
  • Abandoned CDN Domain Re-Registered, Impacting Thousands
  • Microsoft Patches Severe Azure AI Foundry Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Settra Ransomware Threatens Windows Networks
  • WordPress Patch Addresses Click2Shell Vulnerability
  • Feral Wolf Ransomware Exploits Exposed Business Systems
  • Abandoned CDN Domain Re-Registered, Impacting Thousands
  • Microsoft Patches Severe Azure AI Foundry Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark