Progress MOVEit Automation Authentication Bypass | MSSP Advisory
Critical
DateMay 4, 2026
📋Executive Summary
Progress Software patched two security flaws in MOVEit Automation including a critical authentication bypass vulnerability. MOVEit Automation is a server-based managed file transfer solution used to schedule and automate enterprise file movement workflows. The authentication bypass flaw could allow attackers to gain unauthorized access to the MFT system without valid credentials.
⚠️Why It Matters for MSSPs
If your stack includes MOVEit Automation for client file transfers or backup workflows, an authentication bypass puts your entire operation at risk of breach and regulatory exposure. Your clients running MOVEit Automation face immediate compromise of their file transfer infrastructure, and you have a contractual obligation to notify them about this critical patch within hours of availability.
✅Recommended Action
Immediately audit your environment and all client networks for MOVEit Automation installations and push the Progress Software security update to every instance within 24 hours.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.