Massive authentication vulnerability risks compromising much of the internet

Hackers are already exploiting the flaw.
Hacker on laptop
A new exploit found in the enterprise software MOVEit Transfer can have serious consequences for large swaths of the web. Credit: GETTY Images

Another day, another newly discovered exploit. But this vulnerability has the potential to be a really big problem.

This week, Progress Software announced that it had discovered two new items for the common vulnerabilities and exposures (CVE) list of the enterprise product MOVEit Transfer, a popular way for businesses to securely transfer and exchange sensitive files and data. 

This most recent MOVEit vulnerability, known as CVE-2024-5806, allows hackers to bypass authentication protocols and access the potentially sensitive information being transferred.


You May Also Like

While many readers may not be familiar with Progress Software or MOVEit, this vulnerability could result in serious consequences. As Ars Technica points out, a MOVEit vulnerability affected millions of people last year. Thousands of organizations, including the US Department of Energy and Shell, were compromised. The 2023 exploit's effects on the Canadian province of Ontario’s government birth registry alone left 3.4 million people compromised.

Currently, MOVEit is installed on as many as 2,700 networks globally. Bad actors, such as at least one ransomware gang, have already made attempts to exploit this most recent vulnerability, according to cybersecurity researchers with The Shadowserver Foundation and the security firm Censys.

Progress Software has since released a patch to close the exploit, which can be found here.

Topics Cybersecurity

Mashable Potato

Recommended For You
Using AI at work? Then you need to know these 11 AI security risks.
pop art style illustration showing security guards around lock symbol

Clawdbot AI security risks you need to know before trying it
Two digitally animated hands.


Hackers are exploiting a vulnerability in lots of e-commerce sites
Fish-eye lens view of a computer screen with hacking stuff on it

No guarantees: Inside the biggest risks facing NASA's Artemis 2 crew
Artemis 2 crew practicing water recovery after splashdown

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone


Wordle today: Answer, hints for April 2, 2026
Wordle game on a smartphone

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!