CVE-2026-8485: medium-severity vulnerability in Progress Software MOVEit Automation
Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.9epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation.
This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
Progress Software · MOVEit AutomationRelated CVEs — Progress Software MOVEit Automation
In the same product, most dangerous first.
CVE-2026-4670CRITICALImproper Authentication vulnerability in Progress MOVEit AutomationEPSS 0.6%CVE-2026-5174HIGHImproper Access Control Vulnerability in Progress MOVEit AutomationEPSS 0.5%CVE-2026-8486MEDIUMAllocation of resources without limits or throttling vulnerability in Progress Software MOVEit AutomationEPSS 0.5%CVE-2026-8488MEDIUMAllocation of resources without limits or throttling vulnerability in Progress Software MOVEit AutomationEPSS 0.4%CVE-2026-8487MEDIUMIncorrect default permissions vulnerability in Progress Software MOVEit AutomationEPSS 0.3%