CVE-2026-8487Patch(progress / moveit_automation)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch progress moveit_automation systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-276

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • moveit_automation

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
moveit_automation

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-21: 1Patch / Workaround · 2026-05-21: 105-21
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Autumn Good@autumn_good_35
    Patch

    CVE-2026-8485 CVE-2026-8486 CVE-2026-8487 CVE-2026-8488 MOVEit Automation 2026 Release Notes Fixed Issues 2026 https://docs.progress.com/bundle/moveit-automation-release-notes-2026/page/Fixed-Issues-2026.html

    Post summary

    MOVEit Automation 2026 release notes indicate that CVE‑2026‑8485 through CVE‑2026‑8488 have been fixed, but no vulnerability details or exploit information are provided.

    00000345
    6.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprogressmoveit_automation---

Explore more