CVE-2024-5806: Progress MOVEit Transfer
Critical severity, CVSS 9.8. EPSS: 81.5% chance of exploitation in the next 30 days.
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.
Affected products
- Progress MOVEit Transfer: from 2023.0.0, before 2023.0.11 (fixed in 2023.0.11); from 2023.1.0, before 2023.1.6 (fixed in 2023.1.6); version 2024.0.0 only
Published 2024-06-25. Last modified 2026-06-17.