Progress MOVEit Automation Critical Pre-Auth Bypass and Privilege Escalation (CVE-2026-4670, CVE-2026-5174)

Progress MOVEit Automation Critical Pre-Auth Bypass and (TL-2026-0452), also tracked as MOVEit Automation April 2026 Bulletin, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-05-04. It has no confirmed attribution, affects Progress Software MOVEit Automation, references 2 CVEs (CVE-2026-4670, CVE-2026-5174), maps to 26 MITRE ATT&CK techniques (T1003, T1021.002, T1041), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-0452

Threat ID
TL-2026-0452
Also known as
MOVEit Automation April 2026 Bulletin, Airbus SecLab MOVEit Automation Bypass
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
MONITORING
Category
VULNERABILITY
First published
2026-05-04
Last reviewed
2026-05-04
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, state-and-local-government, financial-services, healthcare, manufacturing, energy, education, technology, legal, logistics
Target regions
North America, Europe, Asia-Pacific, Latin America, Global
Detection rules
9
Indicators of compromise
16

Progress Software disclosed two vulnerabilities in MOVEit Automation, the enterprise managed-file-transfer orchestrator. CVE-2026-4670 (CVSS 9.8, CWE-305) is a critical pre-authentication bypass exploitable remotely without privileges or user interaction; CVE-2026-5174 (CVSS 7.7, CWE-20) is a high-severity privilege escalation in the same backend command-port service. Researchers at Airbus SecLab reported both flaws; over 1,400 MOVEit Automation instances are exposed online (Shodan), including more than a dozen tied to U.S. state and local government agencies.

How Progress MOVEit Automation Critical Pre-Auth Bypass and works

On 30 April 2026 Progress Software published a critical security alert bulletin for MOVEit Automation, the workflow-and-scheduling component of the MOVEit managed-file-transfer (MFT) suite used by approximately 3,000 enterprises and 100,000 administrators worldwide. The bulletin describes two distinct vulnerabilities in the service backend command-port interfaces of MOVEit Automation, both reported to Progress by researchers at Airbus SecLab.

CVE-2026-4670 is an authentication bypass by primary weakness (CWE-305) carrying a CVSS 3.1 base score of 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The flaw allows a remote, unauthenticated attacker to reach the backend command-port interface and bypass authentication entirely, gaining administrative control of the MOVEit Automation engine. From that position an attacker can read, modify, or schedule any automation task — including jobs that move sensitive files between SFTP/FTPS/AS2 endpoints, S3/Azure/GCS buckets, and on-prem shares — and can pivot into the host operating system through MOVEit''s task and script execution facilities. The attack requires no user interaction, no privileges, and exhibits low complexity, placing this vulnerability in the highest pre-auth risk tier.

CVE-2026-5174 is an improper input validation flaw (CWE-20) in the same backend command-port surface, carrying a CVSS 3.1 base score of 7.7 (HIGH). The vector is consistent with AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H — network-reachable, low complexity, low-privileged authenticated attacker, scope change, high availability impact — and enables an authenticated actor to escalate privileges or disrupt the automation engine. The two vulnerabilities chain naturally: an attacker who has bypassed authentication via CVE-2026-4670 can leverage CVE-2026-5174 to elevate beyond the access level granted by the bypass and to disrupt automated workflows.

Progress has issued patched releases for every supported branch — 2025.1.5, 2025.0.9, and 2024.1.8 — and stresses that upgrading via the full installer is the only remediation; there is no in-product workaround or hotfix. Versions earlier than 2024.0.0 are end-of-life and remain vulnerable. As of disclosure, no exploitation in the wild has been confirmed by Progress, NVD, or CISA KEV; however, Shodan telemetry shows more than 1,400 internet-exposed MOVEit Automation instances, including over a dozen belonging to U.S. state and local government agencies.

The threat profile is amplified by historical context. In May–June 2023, the CL0P ransomware group exploited a SQL injection zero-day (CVE-2023-34362) in the related product MOVEit Transfer, ultimately compromising more than 2,100 organisations and exposing data on roughly 62 million individuals. CL0P and adjacent extortion crews have since maintained an operational interest in MFT platforms (Cleo, GoAnywhere, MOVEit Transfer) as high-yield ingress points. Although MOVEit Automation differs from MOVEit Transfer in role and codebase, the brand association, the orchestration-level access on offer, and the large exposed surface make CVE-2026-4670 a top-tier candidate for opportunistic mass exploitation by ransomware affiliates and initial-access brokers in the days and weeks following disclosure.

Defenders should patch immediately, restrict MOVEit Automation administrative interfaces to private networks or VPN-fronted access, audit recent automation-task and script-execution history, rotate any credentials stored in MOVEit task definitions, and enable detailed logging on the backend command-port service. CISA''s 2023 MOVEit Transfer playbook (KEV-listed CVE-2023-34362) remains a relevant reference for incident-response posture against this product family.

MITRE ATT&CK techniques used in TL-2026-0452

Credential Access

T1003 OS Credential Dumping; T1552.001 Unsecured Credentials: Credentials In Files

Lateral Movement

T1021.002 Remote Services: SMB/Windows Admin Shares

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Persistence

T1053 Scheduled Task/Job; T1098 Account Manipulation; T1505.003 Server Software Component: Web Shell

Execution

T1059 Command and Scripting Interpreter; T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071.001 Application Layer Protocol: Web Protocols

Collection

T1074.001 Data Staged: Local Data Staging; T1213 Data from Information Repositories

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

Resource Development

T1583 Acquire Infrastructure

Reconnaissance

T1592.002 Gather Victim Host Information: Software; T1595 Active Scanning; T1595.002 Active Scanning: Vulnerability Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Progress MOVEit Automation Critical Pre-Auth Bypass and

  • Progress Software — MOVEit Automation
    Vulnerable versions: All versions earlier than 2024.0.0 (end-of-life); 2024.0.0 through 2024.1.7; 2025.0.0 through 2025.0.8; 2025.1.0 through 2025.1.4
    Fixed in: 2024.1.8; 2025.0.9; 2025.1.5

Remediation for Progress MOVEit Automation Critical Pre-Auth Bypass and

Patches

  • MOVEit Automation 2025.1.5 (fixes the 2025.1.x branch)
  • MOVEit Automation 2025.0.9 (fixes the 2025.0.x branch)
  • MOVEit Automation 2024.1.8 (fixes the 2024.x branch)
  • Versions older than 2024.0.0 are end-of-life and must be upgraded to a supported, fixed branch

Immediate actions

  • Upgrade MOVEit Automation immediately to a fixed branch: 2025.1.5, 2025.0.9, or 2024.1.8 — full installer is the only supported remediation
  • Remove MOVEit Automation administrative and command-port interfaces from direct internet exposure; restrict to management VLAN or VPN-fronted access
  • Block inbound access to the MOVEit Automation backend command port at perimeter and host firewalls until patching is confirmed
  • Rotate every credential stored in MOVEit Automation task definitions, connection profiles, and saved scripts (SFTP, FTPS, AS2, S3/Azure/GCS, SMB, database)
  • Audit MOVEit Automation task history, script-execution logs, and scheduler changes for the trailing 90 days for unauthorised additions or modifications

Workarounds

  • No vendor-supplied workaround exists; full-installer upgrade is the only remediation per Progress
  • Compensating control: place the MOVEit Automation host behind a VPN/zero-trust gateway and restrict inbound access to known administrator source IPs until patched

Longer-term hardening

  • Place MOVEit Automation behind a reverse proxy or WAF with strict allowlists and authenticated-only access
  • Deploy EDR on MOVEit Automation hosts with detections for suspicious child processes spawned by the MOVEit Automation service
  • Segment MFT infrastructure from general corporate network; treat MFT hosts as Tier 1 / crown-jewel assets
  • Subscribe to the Progress Trust Center and Progress security RSS for proactive notification of future advisories
  • Establish a documented MFT patch SLA of less than 72 hours for CRITICAL advisories given the historical CL0P targeting pattern

CVEs associated with Progress MOVEit Automation Critical Pre-Auth Bypass and

CVE-2026-4670, CVE-2026-5174

Weaknesses (CWE) in Progress MOVEit Automation Critical Pre-Auth Bypass and

CWE-305, CWE-20

Timeline of Progress MOVEit Automation Critical Pre-Auth Bypass and

  • CL0P ransomware group exploits CVE-2023-34362 zero-day in Progress MOVEit Transfer (sister product), beginning a campaign that ultimately compromises 2,100+ organisations and exposes data on roughly 62 million individuals — establishing the MOVEit product family as a high-value MFT target.
  • Researchers at Airbus SecLab identify the authentication-bypass and privilege-escalation flaws in the MOVEit Automation backend command-port interfaces and report them privately to Progress Software (approximate window prior to coordinated disclosure).
  • NVD publishes CVE-2026-4670 and CVE-2026-5174 entries crediting Airbus SecLab, with full CVSS 3.1 vectors and affected-version metadata.
  • Progress Software publishes the MOVEit Automation Critical Security Alert Bulletin (April 2026) covering CVE-2026-4670 (CVSS 9.8, CWE-305) and CVE-2026-5174 (CVSS 7.7, CWE-20); fixed releases 2025.1.5, 2025.0.9, and 2024.1.8 are made available.
  • Threadlinqs Intelligence opens TL-2026-0452 to track CVE-2026-4670 / CVE-2026-5174, prioritising it for monitoring given mass-exposure surface and historical CL0P interest in the MOVEit product family.
  • BleepingComputer, GBHackers, and CybersecurityNews publish coverage; Shodan telemetry showing 1,400+ internet-exposed MOVEit Automation instances — including over a dozen tied to U.S. state and local government agencies — drives broader defender awareness.
  • As of 2026-05-29, MOVEit Automation CVE-2026-4670/CVE-2026-5174 remain patched (fixes 2024.1.8/2025.0.9/2025.1.5) with no confirmed in-the-wild exploitation, no public PoC, and absent from CISA KEV (catalog 2026.05.29). 1,400+ exposed instances and Cl0p's history of weaponizing MOVEit flaws warrant continued monitoring for resurgence.

Sources cited for Progress MOVEit Automation Critical Pre-Auth Bypass and

Threats related to Progress MOVEit Automation Critical Pre-Auth Bypass and

Detection coverage for TL-2026-0452

As of 2026-05-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0452 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats