Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2371 articles · 130708 vulns · 36/41 feeds (7d)
← Back to list
9.8
CVE-2026-4670EXPLOITEDPATCHED
progress · moveit automation

Improper Authentication vulnerability in Progress MOVEit Automation

Description

Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

Affected Products

VendorProductVersions
progressmoveit automation2025.0.0, 2024.0.0, 0, 2025.1.4, 2025.0.8, 2024.1.7

References

  • https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174(vendor-advisory)

Related News (2 articles)

Tier B
CCCS Canada2h ago
Progress security advisory (AV26-410)
→ No new info (linked only)
Tier C
VulDB6h ago
CVE-2026-4670 | Progress MOVEit Automation up to 2024.1.7/2025.0.8 authentication bypass
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
2025.0.92024.1.82024.0.0
CWECWE-305, CWE-20
PublishedApr 30, 2026
Last enriched2h agov3
Tags
CVE-2026-4670CVE-2026-5174
Trending Score76
Source articles2
Independent2
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-5174EXP
Improper Access Control Vulnerability in Progress MOVEit Automation
Trending: 61
HIGHCVE-2026-3518
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Trending: 17
HIGHCVE-2026-4048
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Trending: 16
HIGHCVE-2026-6022EXP
Uncontrolled Resource Consumption Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 15
HIGHCVE-2026-3519
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Trending: 15

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 30, 2026
Discovered by ZDM
Apr 30, 2026
Updated: affectedVersions, severity
Apr 30, 2026
Actively Exploited
Apr 30, 2026
Exploit Available
Apr 30, 2026
Patch Available
Apr 30, 2026
Updated: affectedVersions, exploitAvailable, activelyExploited, cweIds, tags
Apr 30, 2026

Version History

v3
Last enriched 2h ago
v3Tier B2h ago

Updated affected versions, marked exploit available and actively exploited, added new CWE and CVE IDs.

affectedVersionsexploitAvailableactivelyExploitedcweIdstags
via CCCS Canada
v2Tier C5h ago

Updated affected versions to include 2024.1.7 and 2025.0.8, changed severity to HIGH, and noted that no exploit exists.

affectedVersionsseverity
via VulDB
v16h ago

Initial creation