CVE-2026-8488 is a medium-severity availability issue in Progress Software MOVEit Automation. The published record describes an allocation-of-resources-without-limits-or-throttling weakness (CWE-770), which can lead to excessive allocation and service degradation if left unpatched. NVD lists the issue as affecting MOVEit Automation before 2025.0.11 and from 2025.1.0 before 2025.1.7.
CVE-2026-8487 is an incorrect default permissions issue affecting Progress Software MOVEit Automation. According to the official NVD summary and Progress release notes reference, the flaw can allow retrieval of embedded sensitive data and affects MOVEit Automation versions before 2025.0.11 and from 2025.1.0 before 2025.1.7. The published CVSS 3.1 vector indicates network access, low attack complexity, low [truncated]
CVE-2026-8486 is a medium-severity availability flaw in Progress Software MOVEit Automation. The issue is described as allocation of resources without limits or throttling, which can allow flooding and degrade service availability. The affected ranges listed in the CVE are versions before 2025.0.11 and versions from 2025.1.0 before 2025.1.7. The NVD record currently lists the vulnerability status as under [truncated]