CRITICAL: Progress MOVEit Automation Hit by 9.8 Auth Bypass With No Workaround
Progress Software disclosed CVE-2026-4670, an unauthenticated authentication bypass in MOVEit Automation rated CVSS 9.8, alongside CVE-2026-5174, a CVSS 7.7 privilege escalation. Patch to 2025.1.5, 2025.0.9, or 2024.1.8. No workarounds exist.