Bleepingcomputer Critical MOVEit Vulnerabilities Expose Organizations to Data Breaches
Article Content
- •Critical vulnerabilities in MOVEit Automation allow for authentication bypass and privilege escalation.
- •Over 1,400 instances of MOVEit Automation are exposed online, including those linked to government agencies.
- •Organizations are urged to upgrade immediately to mitigate risks associated with these vulnerabilities.
Progress Software has issued urgent advisories regarding critical vulnerabilities in its MOVEit Automation platform, specifically CVE-2026-4670 and CVE-2026-5174. These vulnerabilities allow attackers to bypass authentication and escalate privileges, potentially leading to unauthorized access and data exposure. The flaws affect numerous organizations, including U.S. local and state government agencies, with over 1,400 MOVEit Automation instances exposed online. The vulnerabilities were disclosed on April 30, 2026, and require immediate patching to mitigate risks. This follows a significant data breach in 2023, where the Cl0p ransomware gang exploited a zero-day vulnerability in MOVEit, impacting over 2,100 organizations and 62 million individuals. The current situation emphasizes the ongoing risk associated with MOVEit software and the necessity for organizations to update their systems promptly to avoid similar incidents.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (11)
Following this threat?
Track Cl0p, Progress Software and CVE-2026-4670 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Dutch Hacker Arrested in ShinyHunters Investigation Following FBI Breach Dutch authorities arrested Pepijn van der Stap, a 24-year-old previously convicted hacker, on September 15, 2026, as part of an investigation into the ShinyHunters hacking group. This group claimed responsibility for a significant breach of the FBI's job application site, reportedly stealing sensitive data from over…