Vulnerabilities fixed in Progress MOVEit Automation (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Authentication bypass without user interaction (CVE-2026-4670)
- Privilege escalation via improper input validation (CVE-2026-5174)
- Update to version 2025.0.9 or 2024.1.8 required
"The Dutch NCSC has published an advisory about two vulnerabilities in Progress MOVEit Automation. CVE-2026-4670 is an authentication bypass that can be exploited without user interaction. CVE-2026-5174 is an improper input validation leading to privilege escalation. Affected versions: 2025.0.0 to 2025.0.8, 2024.0.0 to 2024.1.7, and all versions before 2024.0.0. Users are advised to upgrade to 2025.0.9 or 2024.1.8 immediately."
no comments yet.