Progress fixes critical authentication flaw in MOVEit Automation
Progress has issued a security bulletin covering two vulnerabilities in MOVEit Automation: CVE-2026-4670, an authentication bypass rated CVSS 9.8, and CVE-2026-5174, a privilege escalation rated CVSS 8.8. If exploited, they may give an attacker unauthorised access and administrative control of the system, leading to data exposure. Affected versions are MOVEit Automation up to and including 2025.1.4, 2025.0.8 and 2024.1.7. Progress strongly recommends upgrading as soon as possible.
What this means for your organisation
MOVEit is used to move files between organisations, often precisely because the content is sensitive: payroll data, patient records, financial files. The product's history makes it an attractive target, and critical flaws here have previously had consequences well beyond the individual installation. If you run MOVEit, you also need to know which data flows pass through it, or you cannot judge the impact of a breach.
Berigo recommends
- Upgrade MOVEit Automation to a fixed version now, and treat it as urgent.
- Restrict access so the solution is not openly reachable from the internet.
- Establish an overview of the data types and counterparties involved in the file transfers.
- Review logs for unexpected administrative logins and configuration changes.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch