Progress Security Update – 03 May 2026

Progress Software Corporation has released a security update to fix two vulnerabilities affecting MOVEit Automation.

The addressed vulnerabilities could allow the attacker to gain elevated privileges or bypass authentication and gain access to the affected system.

The addressed vulnerabilities:

1. Progress MOVEit Automation Authentication Bypass Vulnerability (CVE- 2026-4670):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

2. Progress MOVEit Automation Privilege Escalation Vulnerability (CVE-2026-5174):

  • CVSS: 7.7
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges
Vulnerabilities
  • CVE-2026-4670
  • CVE-2026-5174
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Progress Security Advisory

References