MOVEit automation flaws could enable full system compromise

2026-05-05T02:51:48Z65b2db31686d69047080b43751aa117ac6bd1ddd1dea63503cdd1227e8942d09
AI-assisted-discoveryBluekitCISA-KEVCVE-2026-41940CVE-2026-4670Linux-kernelMOVEitSalt-Typhoonbug-bountycPanelcriticalespionageexploitationphishing-kitsupply-chainvulnerabilityzero-day

What happened

Multiple high-impact vulnerabilities and active threats were reported: Progress fixed critical MOVEit Automation vulnerabilities including an authentication bypass (CVE-2026-4670) and a privilege-escalation bug (CVE-2026-5174) that could enable full system compromise. A critical cPanel flaw (CVE-2026-41940, CVSS 9.3) is being actively exploited against governments, MSPs and hosting providers and was added to CISA’s KEV catalog; CISA also added a Linux kernel flaw (CVE-2026-31431, CVSS 7.8) to KEV. New crimeware and tactics were observed—Bluekit is a feature-rich phishing kit with AI-assisted l

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
65b2db31686d69047080b43751aa117ac6bd1ddd1dea63503cdd1227e8942d09
Enrichment time
2026-05-05T02:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.