A critical authentication bypass vulnerability (CVE-2026-4670) has been disclosed in Progress Software MOVEit Automation. An unauthenticated remote attacker can exploit this flaw entirely over the network — with no privileges and no user interaction required — to bypass authentication controls and gain unauthorized access to the platform.
MOVEit Automation is commonly deployed as an internet-facing file transfer automation server, making exposed instances high-value targets. All versions prior to 2025.0.9 (in the 2025.0.x line), prior to 2024.1.8 (in the 2024.x line), and all versions older than 2024.0.0 are affected. Organizations should patch to a fixed version immediately and review access logs for signs of unauthorized activity.
References:

