Multiple vulnerabilities in Progress MOVEit Transfer (July 31, 2026)
Multiple vulnerabilities have been discovered in Progress MOVEit Transfer. They allow an attacker to cause remote indirect code injection (XSS) and security policy bypass.
CSIRTS triage
- What
- Multiple vulnerabilities allow remote indirect code injection via XSS and bypass of security policies.
- Who is affected
- Deployments of MOVEit Transfer.
- Urgency
- High; security policy bypass and XSS exploitation can compromise file transfer security.
- Action
- Apply Progress security updates for MOVEit Transfer.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch MOVEit Transfer
Get an email when a new MOVEit Transfer advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0951/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-106970.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-159660.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-159670.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-159680.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-10697 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15966 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15967 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15968 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Progress Software MOVEit Transfer: Multiple vulnerabilitiescert-bund
- highCVE-2026-15968: Improper neutralization of input during web page generation ('cross-site scripting') vulnerabi…nvd
- highCVE-2026-15967: Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects …nvd
- highCVE-2026-15966: Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEi…nvd
- highCVE-2026-10697: Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit T…nvd
Recent advisories for Progress MOVEit Transfer
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Progress Software MOVEit Transfer: Multiple vulnerabilitiescert-bund · 2026-07-24
- highCVE-2026-15968: Improper neutralization of input during web page generation ('cross-site scripting') vulnerabi…nvd · 2026-07-23
- highCVE-2026-15967: Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects …nvd · 2026-07-23
- highCVE-2026-15966: Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEi…nvd · 2026-07-23
- highCVE-2026-10697: Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit T…nvd · 2026-07-23
- unknownNCSC-2026-0226 [1.00] [M/H] Vulnerabilities fixed in Progress MOVEit Transferncsc-nl · 2026-07-13
More from CERT-FR Avis de sécurité
- unknownVulnerability in Sonicwall SonicOS (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Wallix products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Cisco products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Nextcloud products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in KeyCloak (August 6, 2026)2026-08-06