CVE-2026-5174Patch(progress / moveit_automation)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch progress moveit_automation systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • moveit_automation

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 26 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 13 signals
  • Technical details provided in 21 signals
  • Disclosure: 7 classified signals
  • General: 4 classified signals
  • Peaked 9d ago at 8 mentions (2026-05-04); latest day: 1
  • 26 total mentions across 11 days

Affected systems

Vendors
Products
moveit_automation

Deep dive

Activity timeline26 mentions / 11d
02468Mentions · 2026-05-01: 4Mentions · 2026-05-04: 8Mentions · 2026-05-05: 4Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-08: 2Mentions · 2026-05-10: 1Mentions · 2026-05-11: 1Mentions · 2026-06-02: 2Mentions · 2026-06-22: 1Mentions · 2026-07-13: 1Active Exploitation · 2026-05-04: 2Active Exploitation · 2026-05-05: 1Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-05-04: 4Patch / Workaround · 2026-05-05: 4Patch / Workaround · 2026-05-08: 2Patch / Workaround · 2026-06-02: 2Technical Details · 2026-05-01: 3Technical Details · 2026-05-04: 7Technical Details · 2026-05-05: 4Technical Details · 2026-05-06: 1Technical Details · 2026-05-08: 2Technical Details · 2026-05-10: 1Technical Details · 2026-05-11: 1Technical Details · 2026-06-02: 1Technical Details · 2026-06-22: 105-0105-0405-0505-0605-0705-0805-1005-1106-0206-2207-13
Signal classification4 categories
Patch
1246.2%
Disclosure
726.9%
General
415.4%
Active Exploitation
311.5%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-05-014
Disclosure2General1Patch1
2026-05-048
Active Exploitation2Disclosure1General1Patch4
2026-05-054
Active Exploitation1Patch3
2026-05-061
Disclosure1
2026-05-071
Disclosure1
2026-05-082
Patch2
2026-05-101
General1
2026-05-111
General1
2026-06-022
Patch2
2026-06-221
Disclosure1
2026-07-131
Disclosure1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Patch

    CVE-2026-4670 (CVSS 9.8 auth bypass) + CVE-2026-5174 (priv esc) both hit the backend command port interfaces — potentially handing attackers admin control and data exposure. No exploits in the wild yet… but no workarounds either. Patches are out. Have you checked your version? 👀

    Post summary

    The post announces two severe CVEs affecting backend command port interfaces, notes that no exploits are currently observed, and highlights the availability of patches.

    3191851818.1K
    1.8M followersView on X
  • Ryan Dewhurst@ethicalhack3r
    Disclosure

    Critical & high vulns in MOVEit Automation enable auth bypass + priv esc via backend command ports. CVE-2026-4670 CVE-2026-5174 MOVEit has been targeted by ransomware groups in the past in mass exploitation campaigns. https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174 @watchtowrcyber https://t.co/PxyjghVrvf

    Post summary

    Progress released a disclosure of two critical MOVEit Automation vulnerabilities (CVE-2026-4670 & CVE-2026-5174) that allow authentication bypass and privilege escalation through backend command ports.

    317236169.3K
    21.1K followersView on X
  • Nicolas Krassas@Dinosn
    General

    MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174) https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174

    Post summary

    The snippet lists a MOVEit Automation security bulletin referencing two CVEs but provides no additional technical details, PoCs, patches, or exploitation evidence.

    030421.2K
    158.1K followersView on X
  • Blue Team News@blueteamsec1
    Disclosure

    MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174) http://dlvr.it/TTW542 #cyber #threathunting #infosec

    Post summary

    The tweet announces a security bulletin for CVE‑2026‑4670 and CVE‑2026‑5174 but provides no details on exploits, patches, or technical specifics.

    020221.2K
    57.2K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『allow authentication bypass and privilege escalation through the service backend command port interfaces』 MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174) https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174

    Post summary

    The bulletin announces a critical vulnerability allowing authentication bypass and privilege escalation via the service backend command port interfaces, providing technical details but no PoC, exploit code, evidence of active exploitation, or patch information.

    00030597
    6.9K followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    【MOVEit AutomationにCritical認証回避、CVE-2026-4670を優先更新】 BleepingComputerは、Progress Softwareが MOVEit Automation の認証回避 CVE-2026-4670 と権限昇格 CVE-2026-5174 を修正したと報じています。CVE-2026-4670は未認証・低複雑性・ユーザー操作不要で悪用可能とされ、CVSS 9.8のCriticalです。 MOVEit Automationはファイル転送ワークフローの自動化基盤であり、業務データ、認証情報、外部連携先が集まりやすい場所です。侵害されると、単なるサーバ侵害ではなく、データ連携経路そのものが乗っ取られる可能性があります。 現時点で悪用確認は明示されていませんが、MFT領域は過去にCl0pなどの大規模窃取キャンペーンで狙われました。修正版への更新、インターネット露出の遮断、監査ログの確認を優先してください。 #MOVEit #CVE20264670 #CVE20265174 #MFT #脆弱性対応 #SOC https://www.bleepingcomputer.com/news/security/moveit-automation-customers-warned-to-patch-critical-auth-bypass-flaw/

    Post summary

    The article announces a critical auth‑bypass vulnerability in MOVEit Automation, reports that a patch is available and urges customers to update, but provides no evidence of active exploitation or PoC.

    10001210
    3.5K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-5174 is a privilege escalation flaw that allows attackers with lower-level access to escalate privileges and gain administrative control. Progress Software has issued an emergency advisory for two critical vulnerabilities in MOVEit Automation, the…

    Post summary

    The text announces CVE-2026-5174 as a privilege escalation flaw and notes an emergency advisory from Progress Software concerning two critical MOVEit Automation vulnerabilities, but it does not provide any PoC, exploit code, or explicit patch details.

    1000049
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    The File Transfer Backdoor: MOVEit Automation Patches Two Critical Flaws (CVE-2026-4670 & CVE-2026-5174) CVE-2026-4670 CVSS 9.8 — Authentication Bypass via Backend Command Port An unauthenticated attacker can bypass authentication on the service backend command port…

    Post summary

    The advisory announces patches for two critical MOVEit Automation vulnerabilities, including CVE-2026-4670, an unauthenticated authentication bypass with a CVSS 9.8 score.

    1000038
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE-2026-4670 · 9.8 → 7.7 The File Transfer Backdoor: MOVEit Automation Patches Two Critical Flaws (CVE-2026-4670 & CVE-2026-5174)

    Post summary

    A patch has been released for two critical CVEs in MOVEit Automation, addressing reported backdoor vulnerabilities.

    1000043
    238 followersView on X
  • Sami Laiho@samilaiho
    Patch

    MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174) URL: https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8

    Post summary

    The bulletin reports two critical CVEs in MOVEit Automation, declares the CVSS severity and official fix, but does not provide PoC, exploit code, or evidence of active exploitation.

    10000544
    30.6K followersView on X
  • iototsecnews@iototsecnews
    General

    Progress MOVEit の脆弱性 CVE-2026-4670/5174 が FIX:認証バイパスと権限昇格の恐れ https://iototsecnews.jp/2026/05/04/critical-moveit-vulnerabilities-enables-authentication-bypass/ 今回の問題の原因は、主に認証プロセスの不備と入力値の検証不足にあります。具体的には、 CVE-2026-4670 (認証バイパス) により未認証のユーザーがシステムへ侵入できてしまう点や、 CVE-2026-5174 (権限昇格) において外部からの入力情報を正しくチェックできず、攻撃者に管理者権限を与えてしまう点が要因となっています。これらの脆弱性が連鎖的に悪用されると、サービスの管理ポートを通じてサーバーの完全な制御を許すリスクが生まれてしまいます。ご利用のチームは、ご注意ください。 #CVE20264670 #CVE20265174 #MOVEit #Progress #Vulnerability

    Post summary

    The post announces the existence of two CVEs in Progress MOVEit with details of authentication bypass and privilege escalation, but does not provide PoC, exploit code, or patch information.

    00000134
    491 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-5174: MOVEit Automation Privilege Escalation Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04g1nK60

    Post summary

    The provided text references a privilege‑escalation bug (CVE‑2026‑5174) in MOVEit Automation but offers no details on exploitation, PoC, patch, or active attacks.

    0000036
    30 followersView on X
  • NOCTIS@NoctisIntel
    Patch

    New CVEs — 2026-05-08 CVE-2026-26956: vm2 3.10.4 sandbox escape → host RCE in Node.js 25. Any app sandboxing user JS via http://VM.run() is vulnerable. CVE-2026-4670 + CVE-2026-5174: MOVEit Automation auth bypass + priv esc. Patch immediately. #CVE202626956 #ZeroDay

    Post summary

    New CVEs announced, including a Node.js sandbox escape leading to host RCE and a MOVEit Automation authentication bypass with privilege escalation, with immediate patch advice provided.

    00000102
    16 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Progress ❗ CVE-2026-5174 ❗ CVE-2026-4670 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-progress-3/ https://t.co/RkRuSryG3b

    Post summary

    The post announces two CVEs—CVE-2026-5174 and CVE-2026-4670—affecting Progress products and provides links for further details, but contains no PoC, exploit code, or mitigation information.

    0000083
    6.7K followersView on X
  • Jason Abernathy@jlabernathy
    Disclosure

    Two critical vulnerabilities identified, CVE-2026-4670 and CVE-2026-5174, with CVSS scores of 9.8 and 7.7 respectively, posing significant risks of authentication bypass and privilege escalation https://thehackernews.com #VulnerabilityManagement

    Post summary

    Two high‑impact vulnerabilities (CVE-2026-4670, CVE-2026-5174) are disclosed with CVSS scores of 9.8 and 7.7, posing authentication bypass and privilege escalation risks. No PoC, exploit details, or patch information are provided.

    0000039
    411 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical vulnerabilities in MOVEit Automation (CVE-2026-4670 & CVE-2026-5174) demand immediate patching to prevent unauthorized access and privilege escalation. Link: https://thedailytechfeed.com/critical-moveit-automation-security-flaws-discovered-immediate-patching-urged/ #MOVEit #Automation #Vulnerability #CVE #Patching #Security #Infosec #Cyberattack #Access #Privilege #Escalation #Exploit #Risk #Threat #Breach #Defense #Compliance #Software #Update #Protection

    Post summary

    The post announces two critical MOVEit Automation CVEs and stresses the need for immediate patching to avoid unauthorized access and privilege escalation.

    0000071
    297 followersView on X
  • Patrik Žák@zakpatrik
    Patch

    Progress varuje před kritickou auth bypass zranitelností v MOVEit Automation (CVE-2026-4670, CVSS 9.8) Progress Software vydal záplaty pro dvě zranitelnosti v MOVEit Automation. Kritická CVE-2026-4670 (CVSS 9.8) umožňuje neautentizovanému vzdálenému útočníkovi obejít autentizaci a získat administrátorský přístup. Druhá CVE-2026-5174 (CVSS 7.7) umožňuje privilege escalation. Zranitelné jsou verze před 2025.1.5, 2025.0.9 a 2024.1.8.

    Post summary

    The post announces that Progress Software has released patches for two critical MOVEit Automation vulnerabilities, describing their severity and impact.

    0000070
    301 followersView on X
  • motch | セキュリティ🛡️@motch_dev
    Patch

    ■ 何が起きたか Progress SoftwareがMOVEit Automationの認証バイパス脆弱性(CVE-2026-4670)と特権昇格の脆弱性(CVE-2026-5174)を修正した。Airbus SecLabの研究者が報告し、現時点で悪用の報告はないが、同社は至急パッチ適用を推奨している。 ■ 技術詳細 CVE-2026-4670はサービスバックエンドのコマンドポートインターフェースにおける認証バイパスで、リモートの未認証攻撃者が低複雑度の攻撃で悪用可能。CVE-2026-5174は不適切な入力検証に起因する特権昇格で、認証済み攻撃者が権限を昇格させる。両者を組み合わせると完全な管理者制御が奪取される可能性がある。 ■ 影響範囲 対象はMOVEit Automation 2025.1.4以前、2025.0.8以前、2024.1.7以前。Shodanの調査では1,400超のインスタンスがオンラインで露出しており、うち16件が米国の州・地方政府機関に関連する。攻撃成功時はタスクに保存された認証情報や機密データ(給与、財務ファイルなど)が窃取され、ランサムウェアグループによる大規模データ窃取キャンペーンに悪用されるリスクがある。 ■ 対策 修正版は2025.1.5、2025.0.9、2024.1.8。フルインストーラによるアップグレードのみが唯一の対策で、アップグレード中はシステム停止が発生する。監査ログで予期しない特権昇格や不正アクセスを確認することで悪用の兆候を検知できる。 #MOVEit

    Post summary

    Progress Software released patches for two Moveit Automation CVEs after researchers identified an authentication bypass and privilege escalation; no exploitation has been reported yet, but organizations are urged to apply the upgrades promptly.

    0000057
    270 followersView on X
  • ThreatAft@ThreatAft
    Active Exploitation

    🚨 MOVEit is back in the headlines. CVE-2026-4670 — CVSS 9.8 No login needed. Full admin access. 1,400+ instances exposed online. US govt agencies included. No workaround. Patch or you're next. 🔗 https://threataft.com/articles/moveit-automation-auth-bypass-privilege-escalation-cve-2026-4670-cve-2026-5174 #CyberSecurity #ThreatIntel #MOVEit #CVE #Infosec

    Post summary

    The tweet highlights CVE-2026-4670 in MOVEit with a CVSS of 9.8, noting that it allows full admin access without login and that over 1,400 instances, including U.S. government systems, are exposed—indicating active exploitation and stressing the need for immediate patching.

    0000089
    18 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers chained CVE-2026-4670 authentication bypass with CVE-2026-5174 privilege escalation to gain administrative control over MOVEit Automation systems. TRC analysis shows lateral movement followed, enabling access to sensitive file transfer data. Runtime segmentation helps contain such post-compromise activity. #ZeroTrust 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/progress-patches-critical-moveit-automation-bug-enabling-authentication-bypass-cve-2026-4670

    Post summary

    The post reports real-world exploitation of two CVEs in MOVEit Automation, detailing how attackers chained an authentication bypass with a privilege escalation to gain administrative control, though it does not provide a PoC, exploit code, or patch information.

    0000060
    1.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprogressmoveit_automation---

Explore more