CVE-2024-5806Active Exploitation(progress / moveit_transfer)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch progress moveit_transfer systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • moveit_transfer

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-03-19); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
moveit_transfer

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-12: 1Mentions · 2026-03-19: 3Mentions · 2026-08-27: 1Mentions · 2026-09-19: 1Active Exploitation · 2026-03-19: 1Active Exploitation · 2026-08-27: 1Active Exploitation · 2026-09-19: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-09-19: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-19: 103-1203-1908-2709-19
Signal classification3 categories
Active Exploitation
466.7%
Patch
116.7%
General
116.7%
Classification over time
DateTotalLabels
2026-03-121
Patch1
2026-03-193
Active Exploitation2General1
2026-08-271
Active Exploitation1
2026-09-191
Active Exploitation1
Full discourse6 posts
  • David@davidsheyi
    Active Exploitation

    2/ CVE-2024-5806 allows attackers to execute arbitrary code. This vulnerability is already a target for known groups. #ThreatIntel #Exploit

    Post summary

    The tweet announces CVE‑2024‑5806 as a remote code execution flaw that is already a target for known threat groups, implying potential active exploitation.

    1000061
    555 followersView on X
  • David@davidsheyi
    Active Exploitation

    MOVEit Transfer zero-day CVE-2024-5806 actively exploited. Here is what organizations must do immediately #MOVEit #ZeroDay #CyberSecurity

    Post summary

    The post declares that the zero‑day CVE‑2024‑5806 is being actively exploited but offers no PoC, exploit code, patch details, or technical description.

    1000079
    555 followersView on X
  • David@davidsheyi
    Patch

    1/ The MOVEit vulnerability CVE-2024-5806 allows attackers to execute arbitrary code. PATCH NOW to prevent unauthorized access #CVE #Vulnerability

    Post summary

    The tweet highlights the MOVEit CVE-2024-5806 vulnerability that permits arbitrary code execution and urges immediate patching to prevent unauthorized access.

    10000111
    555 followersView on X
  • ro0TCr4k@ro0TCr4k
    Active Exploitation

    MOVEit zero-day CVE-2024-5806 is actively exploited. Sysadmins: patch now or segment until you can. RootCrak advisories are live—stay ahead, don't become the case study.

    Post summary

    The tweet reports that MOVEit zero-day CVE-2024-5806 is actively exploited in the wild and urges sysadmins to apply patches or segment their systems immediately, with advisories available from RootCrak.

    00000119
    511 followersView on X
  • ro0TCr4k@ro0TCr4k
    Active Exploitation

    The MOVEit zero-day (CVE-2024-5806) is being exploited in the wild. Attackers are chaining it with prior vulnerabilities. If you're running MOVEit, patching is no longer optional—it's critical. RootCrak is actively tracking the IOCs.

    Post summary

    CVE-2024-5806 in MOVEit is actively exploited in the wild, requiring immediate patching; RootCrak tracks related IOCs.

    00000109
    470 followersView on X
  • David@davidsheyi
    General

    11/ Stay informed with resources from CISA and NIST for best practices and defensive measures against CVE-2024-5806. Act now! #Security #CVE #InfoSec #CISO

    Post summary

    Advisory urges users to consult CISA and NIST resources for defensive measures against CVE‑2024‑5806, but lacks specific exploitation or remediation details.

    0000050
    555 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appprogressmoveit_transfer---
Appprogressmoveit_transfer2024.0.0--

Explore more