CVE-2026-4670Patch(progress / moveit_automation)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 21 mentions and remains active

Immediate actions

  • Patch progress moveit_automation systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-305

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • moveit_automation

Threat summary

  • Active exploitation appears in 11 classified signals
  • Patch or workaround signal is available
  • 69 mentions across 15 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 11 signals
  • Patch or workaround mentioned in 35 signals
  • Technical details provided in 56 signals
  • Disclosure: 18 classified signals
  • Peaked 13d ago at 21 mentions (2026-05-04); latest day: 1
  • 69 total mentions across 15 days

Affected systems

Vendors
Products
moveit_automation

Deep dive

Activity timeline69 mentions / 15d
05111621Mentions · 2026-05-01: 5Mentions · 2026-05-04: 21Mentions · 2026-05-05: 15Mentions · 2026-05-06: 4Mentions · 2026-05-07: 1Mentions · 2026-05-08: 4Mentions · 2026-05-11: 2Mentions · 2026-05-12: 1Mentions · 2026-05-14: 6Mentions · 2026-05-24: 1Mentions · 2026-06-02: 3Mentions · 2026-06-05: 1Mentions · 2026-06-22: 3Mentions · 2026-07-13: 1Mentions · 2026-08-13: 1Active Exploitation · 2026-05-04: 4Active Exploitation · 2026-05-05: 3Active Exploitation · 2026-05-08: 1Active Exploitation · 2026-05-12: 1Active Exploitation · 2026-05-24: 1Active Exploitation · 2026-06-05: 1Patch / Workaround · 2026-05-01: 2Patch / Workaround · 2026-05-04: 13Patch / Workaround · 2026-05-05: 10Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-08: 3Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-06-02: 2Patch / Workaround · 2026-06-05: 1Technical Details · 2026-05-01: 4Technical Details · 2026-05-04: 19Technical Details · 2026-05-05: 11Technical Details · 2026-05-06: 3Technical Details · 2026-05-08: 4Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 1Technical Details · 2026-05-14: 5Technical Details · 2026-06-02: 2Technical Details · 2026-06-05: 1Technical Details · 2026-06-22: 3Technical Details · 2026-08-13: 105-0105-0405-0505-0605-0705-0805-1105-1205-1405-2406-0206-0506-2207-1308-13
Signal classification5 categories
Patch
3043.5%
Disclosure
1826.1%
Active Exploitation
1115.9%
General
913.0%
False Positive
11.4%
Referenced assets33 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-015
Disclosure2General1Patch2
2026-05-0421
Active Exploitation4Disclosure3General1Patch13
2026-05-0515
Active Exploitation3Disclosure2General1Patch9
2026-05-064
Disclosure2General1Patch1
2026-05-071
General1
2026-05-084
Active Exploitation1Disclosure2Patch1
2026-05-112
Disclosure1Patch1
2026-05-121
Active Exploitation1
2026-05-146
Disclosure3False Positive1General2
2026-05-241
Active Exploitation1
2026-06-023
Disclosure1Patch2
2026-06-051
Active Exploitation1
2026-06-223
Disclosure2General1
2026-07-131
General1
2026-08-131
Patch1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Patch

    CVE-2026-4670 (CVSS 9.8 auth bypass) + CVE-2026-5174 (priv esc) both hit the backend command port interfaces — potentially handing attackers admin control and data exposure. No exploits in the wild yet… but no workarounds either. Patches are out. Have you checked your version? 👀

    Post summary

    Two critical CVEs affecting backend command interfaces are disclosed; patches are available, and no active exploitation has been observed yet.

    3191851818.1K
    1.8M followersView on X
  • Ryan Dewhurst@ethicalhack3r
    Disclosure

    Critical & high vulns in MOVEit Automation enable auth bypass + priv esc via backend command ports. CVE-2026-4670 CVE-2026-5174 MOVEit has been targeted by ransomware groups in the past in mass exploitation campaigns. https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174 @watchtowrcyber https://t.co/PxyjghVrvf

    Post summary

    The tweet announces two critical and high‑severity vulnerabilities, CVE‑2026‑4670 and CVE‑2026‑5174, in MOVEit Automation that allow authentication bypass and privilege escalation via backend command ports.

    317236169.3K
    21.1K followersView on X
  • Censys@censysio
    Disclosure

    🚨 CVE-2026-4670 (CVSS 9.8) MOVEit Automation Authentication Bypass Auth bypass in MOVEit Automation: potential admin access and data exposure. No exploitation yet, but impact could be significant if workflow is accessed. We’re seeing <100 exposed instances globally. Details: https://bit.ly/48KW7Z8 #CVE20264670 #MOVEit #infosec

    Post summary

    The post announces a high‑severity authentication bypass in MOVEit Automation (CVE‑2026‑4670) with potential admin access and data exposure, but notes no exploitation or patch yet.

    31103493.1K
    12.5K followersView on X
  • Michael Martino@battista212
    Patch

    MOVEit Automation has a critical auth bypass (CVE-2026-4670). Remotely exploitable, no privileges needed. Clop mass-exploited MFT platforms before. If you run MOVEit: upgrade NOW and audit exposure. #Cybersecurity #InfoSec https://t.co/A9OuLdlIe8

    Post summary

    The text warns of a remotely exploitable authentication bypass (CVE-2026-4670) in MOVEit Automation and urges immediate upgrade to mitigate potential exploitation.

    220711.0K
    238 followersView on X
  • Nicolas Krassas@Dinosn
    General

    MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174) https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174

    Post summary

    The text simply references a MOVEit Automation Security Alert Bulletin that lists two CVEs but provides no detailed information or actionable content.

    030421.2K
    158.1K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    MOVEit Automation faces a critical 9.8 CVSS flaw (CVE-2026-4670). Attackers can bypass auth to seize admin control and expose data. Patch immediately. #MOVEit #CyberSecurity #InfoSec #DataBreach #PatchNow #ProgressSoftware #VulnerabilityAlert https://securityonline.info/moveit-automation-authentication-bypass-cve-2026-4670-patch-alert/ https://t.co/zvaslgAKEk

    Post summary

    The post announces the critical CVE‑2026‑4670 authentication bypass in MOVEit Automation and urges users to apply a patch immediately, providing a link to a patch advisory.

    03040630
    12.5K followersView on X
  • Blue Team News@blueteamsec1
    General

    MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174) http://dlvr.it/TTW542 #cyber #threathunting #infosec

    Post summary

    The tweet announces a MOVEit Automation security bulletin for CVE‑2026‑4670 and CVE‑2026‑5174, but provides no detailed technical or exploit information.

    020221.2K
    57.2K followersView on X
  • 🛡️Shir Khorshid Noor Cyber Unit🛡️@FriendOfTheInst
    Active Exploitation

    ⚠️ Threat landscape update: exploitation pressure is intensifying across edge devices, Linux infrastructure, AI stacks, managed file transfer systems, and education platforms. Purple Ops’ May 11 CTI brief highlights a convergence of high-impact risks: • PAN-OS CVE-2026-0300: actively exploited unauthenticated RCE against exposed Palo Alto Networks User-ID Authentication Portals, enabling root-level compromise. • Linux Copy Fail / Dirty Frag: local privilege escalation paths targeting kernel page-cache behavior, with serious post-compromise impact for cloud, container, and enterprise Linux environments. • MOVEit Automation CVE-2026-4670: critical authentication bypass risk affecting sensitive workflow and file-transfer operations. • Ollama “Bleeding Llama” CVE-2026-7482: unauthenticated memory leakage risk exposing prompts, system prompts, environment variables, and potentially API keys. • Canvas / ShinyHunters: large-scale education-sector breach claims involving thousands of institutions and hundreds of millions of users. • Ransomware activity remains broad, with Purple Ops tracking 226 victims across 38 active groups; The Gentlemen, Qilin, Medusa Locker, SafePay, and Akira led observed activity. Defensive priorities: ✅ Patch exposed edge, MFT, Linux, AI, and mobile management systems ✅ Restrict internet exposure of admin/authentication portals ✅ Hunt for privilege escalation and post-exploitation behavior ✅ Audit AI infrastructure and model-serving endpoints ✅ Monitor ransomware leak-site activity and credential exposure ✅ Treat actor-claimed dark-web leaks as intelligence leads, not verified facts, until confirmed The signal is clear: attackers are chaining edge exploitation, privilege escalation, AI infrastructure exposure, credential theft, and extortion faster than many organizations can patch. #CyberSecurity #ThreatIntelligence

    Post summary

    The brief highlights that several CVEs, notably PAN-OS CVE-2026-0300, are actively exploited in the wild, urging immediate patching of edge, MFT, Linux, and AI systems to thwart chained attacks.

    00120206
    561 followersView on X
  • Securízame@Securizame
    Patch

    Progress corrige un bypass crítico de autenticación en MOVEit Automation (CVE-2026-4670) https://unaaldia.hispasec.com/2026/05/progress-corrige-un-bypass-critico-de-autenticacion-en-moveit-automation-cve-2026-4670.html #Internet #Noticia #Tecnología #ciberSeguridad vía @unaaldia https://t.co/3lqNL6654X

    Post summary

    Progress has released a patch to address a critical authentication bypass (CVE‑2026‑4670) in MOVEit Automation; the tweet contains no evidence of active exploitation or exploit code.

    00030207
    15.4K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-41940 2 - CVE-2026-31431 3 - CVE-2026-4670 4 - CVE-2026-3854 5 - CVE-2026-1281 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVEs with no additional technical or contextual information.

    00012158
    1.7K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『allow authentication bypass and privilege escalation through the service backend command port interfaces』 MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174) https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174

    Post summary

    The bulletin announces CVE-2026-4670 and CVE-2026-5174, noting authentication bypass and privilege escalation via backend command ports, but does not provide PoC, exploit code, or patch details.

    00030597
    6.9K followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    【MOVEit AutomationにCritical認証回避、CVE-2026-4670を優先更新】 BleepingComputerは、Progress Softwareが MOVEit Automation の認証回避 CVE-2026-4670 と権限昇格 CVE-2026-5174 を修正したと報じています。CVE-2026-4670は未認証・低複雑性・ユーザー操作不要で悪用可能とされ、CVSS 9.8のCriticalです。 MOVEit Automationはファイル転送ワークフローの自動化基盤であり、業務データ、認証情報、外部連携先が集まりやすい場所です。侵害されると、単なるサーバ侵害ではなく、データ連携経路そのものが乗っ取られる可能性があります。 現時点で悪用確認は明示されていませんが、MFT領域は過去にCl0pなどの大規模窃取キャンペーンで狙われました。修正版への更新、インターネット露出の遮断、監査ログの確認を優先してください。 #MOVEit #CVE20264670 #CVE20265174 #MFT #脆弱性対応 #SOC https://www.bleepingcomputer.com/news/security/moveit-automation-customers-warned-to-patch-critical-auth-bypass-flaw/

    Post summary

    The post reports that MOVEit Automation’s critical authentication bypass (CVE‑2026‑4670) has been patched and urges timely updates and additional mitigations.

    10001210
    3.5K followersView on X
  • Help Net Security@helpnetsecurity
    Patch

    Critical MOVEit Automation auth bypass vulnerability fixed (CVE-2026-4670) - https://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/ - @ProgressSW #MOVEit #FileTransfer #Enterprise #vulnerability #CybersecurityNews #InfosecNews #ITsec

    Post summary

    The post reports that the MOVEit Automation authentication bypass vulnerability (CVE‑2026‑4670) has been fixed, indicating the vendor has released a patch.

    00002338
    60.1K followersView on X
  • Stanislav Klevtsov@stansecure
    Patch

    Top #CVE to #patch this week 👀 - @VMware #ESXi 9.0 RCE (CVE-2026-47876, CVE-2026-41703) - @JetBrains #TeamCity RCE (CVE-2026-63077, CVE-2026-65907) - #Jenkins Core (CVE-2026-70426) - @zohocorp ManageEngine ADAudit RCE (CVE-2026-6516) - @IBM Langflow RCE (CVE-2026-9198) - @ApacheKylin OS command injection (CVE-2026-62392) - #MOVEit auth bypass (CVE-2026-4670) - @giteaio unauth file read (CVE-2026-59774)

    Post summary

    The tweet enumerates several recent CVEs that need patching, highlighting their general impact types but offering no exploit details or specific remediation steps.

    1000073
    44 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Attack Vector: The authentication bypass in CVE-2026-4670 likely stems from improper validation of user credentials or session tokens, allowing attackers to construct requests that bypass access controls entirely. This is a network-based vulnerability with no user…

    Post summary

    The passage outlines technical details of CVE‑2026‑4670’s authentication bypass but does not mention PoC, exploit code, active attacks, patches, or debunking.

    1000034
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    4670 allows — CVE-2026-4670: MOVEit Automation Authentication Bypass — Unauthenticated Access to Enterprise File Transfer. Progress Software has issued an emergency advisory for two critical vulnerabilities in MOVEit Automation, the enterprise-grade managed file transfer…

    Post summary

    Progress Software issued an emergency advisory for CVE-2026-4670, highlighting an authentication bypass that allows unauthenticated access to MOVEit Automation.

    1000055
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-4670 is a critical authentication bypass flaw that allows attackers to access MOVEit Automation systems without valid credentials. No legitimate user account is required to exploit this vulnerability.

    Post summary

    CVE‑2026‑4670 is a critical authentication bypass in MOVEit Automation that permits unauthenticated access without any valid credentials.

    1000051
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-4670 (MOVEit): CVSS 9.8 auth bypass. No patch available. Active exploitation confirmed. The TTE Equation Is Broken: Why Enterprise Can't Patch Faster Than Attackers Exploit

    Post summary

    The post reports that CVE-2026-4670 for MOVEit, a critical authentication bypass with a CVSS score of 9.8, is being actively exploited in the wild and currently has no patch available.

    1000086
    246 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-4670 (CVSS 9.8) — Authentication Bypass via Backend Command Port An unauthenticated attacker can bypass authentication on the service backend command port interface through low-complexity attacks. No valid credentials required. No user interaction needed. Direct…

    Post summary

    The snippet announces CVE-2026-4670, a high‑severity authentication bypass on a backend command port that requires no credentials or user interaction, without any mention of exploitation or mitigation.

    1000035
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE-2026-4670 · 9.8 → 7.7 The File Transfer Backdoor: MOVEit Automation Patches Two Critical Flaws (CVE-2026-4670 &amp; CVE-2026-5174)

    Post summary

    The text announces vendor patches for CVE-2026-4670 and CVE-2026-5174 in MOVEit Automation, noting a CVSS adjustment for the former.

    1000043
    238 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprogressmoveit_automation---

Explore more