« Back to list

Progress

Progress Moveit Automation: vulnerabilities and CVEs

Progress Moveit Automation has 8 published vulnerabilities, 6 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs8
Last 12 months6
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-8488High (7.5)0.45%—May 20, 2026
Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before…
CVE-2026-8487High (7.5)0.34%—May 20, 2026
Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.
CVE-2026-8486High (7.5)0.49%—May 20, 2026
Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.
CVE-2026-8485High (7.5)0.43%—May 20, 2026
Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.
CVE-2026-5174High (8.8)0.50%—Apr 30, 2026
Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from…
CVE-2026-4670Critical (9.8)0.61%—Apr 30, 2026
Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before…
CVE-2024-4563High (7.5)0.24%—May 22, 2024
The Progress MOVEit Automation configuration export function prior to 2024.0.0 uses a cryptographic method with insufficient bit length.
CVE-2020-12677Medium (6.1)1.9%—May 14, 2020
An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately sanitize malicious input, which could allow an unauthenticated attacker to execute arbitrary code in…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application5
  2. T1499.004 Application or System Exploitation2
  3. T1068 Exploitation for Privilege Escalation1
  4. T1078.001 Default Accounts1
  5. T1210 Exploitation of Remote Services1
  6. T1499 Endpoint Denial of Service1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Progress