The following issues were fixed in MOVEit Automation 2025.1.7.

ID

Category

Fixed Issue

100853

SharePoint

The SharePoint PUT script now uploads complete file contents for all supported file types.

100950

Server

Password encryption and decryption logic has been updated to increase buffer limitations, allowing larger passwords to be used.

101151

Security, Server

CVE-2026-8485: Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation.

101152

Security, Endpoints, Server

CVE-2026-8486: Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation.

101153

Security

CVE-2026-8487: Incorrect default permissions vulnerability in Progress Software MOVEit Automation.

101156

Security, Server

CVE-2026-8488: Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation.

103818

HTTPS

Public key requests from the Server to Web Admin now correctly ignore environment‑level proxy settings, preventing connection issues.

101036, 101192, 101193, 101302, 101612, 102638, 103555

Security, Web Admin, Server, Database

Multiple third-party components used by MOVEit Automation have been updated to newer supported versions, including Spring Security, Spring Boot, OpenSSL, Tomcat, OpenJDK, libcurl, Bouncy Castle, and selected JavaScript libraries. These updates improve overall security and prevent potential vulnerabilities.