← All Advisories

Critical Progress MOVEit Automation Authentication Bypass Scores 9.8

Last refreshed2026-09-26

Status: EPSS-IMMINENT  |  Advisory ID: CVE-2026-4670

Key Details

CVECVE-2026-4670
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-09-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsProgress MOVEit Automation
Classified asCWE-305 (Authentication Bypass by Primary Weakness)
Exploitation prediction (EPSS)0.61% probability of exploitation in the next 30 days (47% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
ProgressMOVEit Automation
SubsystemsGeneral OT
SectorsMultiple

What to Know

Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass.

This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

What to Do

Monitor Progress's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-4670
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-4670
Vendor advisoryhttps://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174