Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2371 articles · 130716 vulns · 36/41 feeds (7d)
← Back to list
7.7
CVE-2026-5174EXPLOITEDPATCHED
progress · moveit automation

Improper Access Control Vulnerability in Progress MOVEit Automation

Description

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

Affected Products

VendorProductVersions
progressmoveit automation2025.1.0, 2025.0.0, 2024.0.0, 0, 2025.1.4, 2025.0.8, 2024.1.7

References

  • https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174(vendor-advisory)

Related News (2 articles)

Tier B
CCCS Canada4h ago
Progress security advisory (AV26-410)
→ No new info (linked only)
Tier C
VulDB7h ago
CVE-2026-5174 | Progress MOVEit Automation up to 2024.1.7/2025.0.8/2025.1.4 input validation
→ No new info (linked only)
CVSS 3.17.7 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
2025.1.52025.0.92024.1.82024.0.0
CWECWE-20
PublishedApr 30, 2026
Last enriched3h agov3
Trending Score60
Source articles2
Independent2
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-4670EXP
Improper Authentication vulnerability in Progress MOVEit Automation
Trending: 75
HIGHCVE-2026-3518
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Trending: 17
HIGHCVE-2026-4048
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Trending: 16
HIGHCVE-2026-6022EXP
Uncontrolled Resource Consumption Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 15
HIGHCVE-2026-3519
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Trending: 15

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 30, 2026
Discovered by ZDM
Apr 30, 2026
Updated: affectedVersions
Apr 30, 2026
Actively Exploited
Apr 30, 2026
Exploit Available
Apr 30, 2026
Patch Available
Apr 30, 2026
Updated: affectedVersions, severity, exploitAvailable, activelyExploited
Apr 30, 2026

Version History

v3
Last enriched 3h ago
v3Tier B3h ago

Updated affected versions to include 2025.1.4, 2025.0.8, and 2024.1.7, changed severity to CRITICAL, and marked exploit as available and actively exploited.

affectedVersionsseverityexploitAvailableactivelyExploited
via CCCS Canada
v2Tier C7h ago

Updated affected versions to include 2024.1.7, 2025.0.8, and 2025.1.4, and noted that no exploit is available.

affectedVersions
via VulDB
v17h ago

Initial creation