CVE-2024-5806: Progress MOVEit Transfer

Critical severity, CVSS 9.8. EPSS: 81.5% chance of exploitation in the next 30 days.

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

Affected products

  • Progress MOVEit Transfer: from 2023.0.0, before 2023.0.11 (fixed in 2023.0.11); from 2023.1.0, before 2023.1.6 (fixed in 2023.1.6); version 2024.0.0 only

Published 2024-06-25. Last modified 2026-06-17.