Junglewise Threat Intelligence

CVE-2026-8486: Progress Software MOVEit Automation resource exhaustion via flooding

CVE-2026-8486 · Severity: medium · CVSS 5.3 · Published 2026-05-20

Technologies: Progress Software MOVEit Automation. Vendors: Progress Software.

Executive brief

Progress Software MOVEit Automation is a managed file transfer solution used to automate complex data workflows. A vulnerability in how the system manages incoming requests could allow an attacker to flood the service with data, potentially leading to a slowdown or temporary unavailability of file transfer operations. This could disrupt automated business processes and scheduled data movements.

Technical details

A resource management vulnerability (CWE-770) exists in Progress Software MOVEit Automation due to a lack of proper limits or throttling on resource allocation. An unauthenticated remote attacker can exploit this by sending a high volume of requests or data (flooding), leading to resource exhaustion. This impact is primarily limited to availability (DoS), as reflected in the CVSS score. The issue is resolved in MOVEit Automation versions 2025.0.11, 2025.1.7, and the 2026 release.

Affected products

  • Progress Software MOVEit Automation before 2025.0.11, 2025.1.0 before 2025.1.7

Timeline

  • 2026-05-18: patched: Release notes for MOVEit Automation 2026 published.
  • 2026-05-20: advisory: CVE published to NVD.

References

Related threats