Multiple vulnerabilities in Progress MOVEit Transfer (July 10, 2026)
Multiple vulnerabilities have been discovered in Progress MOVEit Transfer. Some of them allow an attacker to cause privilege escalation, data confidentiality breaches, and remote indirect code injection (XSS).
CSIRTS triage
- What
- Multiple vulnerabilities in Progress MOVEit Transfer could allow privilege escalation, data confidentiality breaches, and remote indirect code injection.
- Who is affected
- Users of Progress MOVEit Transfer.
- Urgency
- Remediation is urgent due to the potential for significant security breaches.
- Action
- Install the latest security updates for Progress MOVEit Transfer.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch MOVEit Transfer
Get an email when a new MOVEit Transfer advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0856/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-119030.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-106990.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-106980.64% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-11903 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-10699 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-10698 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0226 [1.00] [M/H] Vulnerabilities fixed in Progress MOVEit Transferncsc-nl
- high[NEW] [high] Progress Software MOVEit: Multiple vulnerabilitiescert-bund
- criticalProgress security advisory (AV26-678)cccs
- highCVE-2026-11903: Improper neutralization of input during web page generation ('cross-site scripting') vulnerabi…nvd
- highCVE-2026-10699: Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (…nvd
- highCVE-2026-10698: Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVE…nvd
Recent advisories for Progress MOVEit Transfer
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMultiple vulnerabilities in Progress MOVEit Transfer (July 31, 2026)cert-fr-avis · 2026-07-31
- medium[NEW] [medium] Progress Software MOVEit Transfer: Multiple vulnerabilitiescert-bund · 2026-07-24
- highCVE-2026-15968: Improper neutralization of input during web page generation ('cross-site scripting') vulnerabi…nvd · 2026-07-23
- highCVE-2026-15967: Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects …nvd · 2026-07-23
- highCVE-2026-15966: Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEi…nvd · 2026-07-23
- highCVE-2026-10697: Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit T…nvd · 2026-07-23
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21