Progress MOVEit Automation Auth Bypass RCE | MSSP Advisory
Critical
DateMay 4, 2026
📋Executive Summary
Progress Software patched a critical authentication bypass vulnerability (CVE-2026-4670) and privilege escalation flaw (CVE-2026-5174) in MOVEit Automation that could grant attackers unauthorized access and administrative control. Airbus researchers discovered these flaws privately with no evidence of active exploitation, but Progress strongly recommends immediate upgrades to fixed versions.
⚠️Why It Matters for MSSPs
MOVEit runs in many MSSP client environments for secure file transfers, and an authentication bypass means attackers can walk right past login screens to access sensitive data transfers. Your clients are sitting ducks if they run unpatched MOVEit Automation, and explaining why you knew about critical file transfer vulnerabilities but said nothing kills retention faster than ransomware.
✅Recommended Action
Scan all client environments for MOVEit Automation installations within 24 hours and push emergency patches to the latest fixed version immediately.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.