VendorsProgressmoveit_automationall versions
Vulnerabilities

Progress MOVEit Automation

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-4670
Improper Authentication vulnerability in Progress MOVEit Automation
Published 2026-04-30 · Analyzed
9.8EPSS 0.006
CVE-2026-5174
Improper Access Control Vulnerability in Progress MOVEit Automation
Published 2026-04-30 · Analyzed
8.8EPSS 0.005
CVE-2026-8486
Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation
Published 2026-05-20 · Analyzed
7.5EPSS 0.005
CVE-2026-8488
Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation
Published 2026-05-20 · Analyzed
7.5EPSS 0.004
CVE-2026-8485
Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation
Published 2026-05-20 · Analyzed
7.5EPSS 0.004
CVE-2026-8487
Incorrect default permissions vulnerability in Progress Software MOVEit Automation
Published 2026-05-20 · Analyzed
7.5EPSS 0.003
CVE-2024-4563
The Progress MOVEit Automation Configuration Export Function Uses a Cryptographic Method with Insufficient Bit Length
Published 2024-05-22 · Analyzed
7.5EPSS 0.002
CVE-2020-12677
An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately sanitize malicious input, which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS. This affects 2018 - 2018.0 prior to 2018.0.3, 2018 SP1 - 2018.2 prior to 2018.2.3, 2018 SP2 - 2018.3 prior to 2018.3.7, 2019 - 2019.0 prior to 2019.0.3, 2019.1 - 2019.1 prior to 2019.1.2, and 2019.2 - 2019.2 prior to 2019.2.2.
Published 2020-05-14 · Modified
6.1EPSS 0.019