NCSC-2026-0226 [1.00] [M/H] Vulnerabilities fixed in Progress MOVEit Transfer
Progress has fixed vulnerabilities in MOVEit Transfer, specifically in the Custom Reports modules and the Ad Hoc module. The vulnerabilities affect multiple versions of MOVEit Transfer, including 25.0.0 to 25.0.7, 25.1.0 to 25.1.3, and 26.0.0 up to just before 26.0.1. One vulnerability in the Custom Reports modules involves improper neutralization of special elements within data query logic, allowing query parameters to be manipulated, which can lead to unauthorized data access or corruption. Additionally, there is a memory release vulnerability in the same modules related to memory lifetime, which can result in improper memory management. Furthermore, there is a cross-site scripting (XSS) vulnerability in the Ad Hoc module, caused by improper input neutralization, allowing malicious scripts to be injected and executed within the context of the application.
CSIRTS triage
- What
- Vulnerabilities allow unauthorized data access, memory management issues, and XSS attacks.
- Who is affected
- Users of MOVEit Transfer versions within the specified range are affected.
- Urgency
- Remediation is urgent due to the potential for unauthorized access and data corruption.
- Action
- Update MOVEit Transfer to the latest version to address these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch MOVEit Transfer
Get an email when a new MOVEit Transfer advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0226
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-106980.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all scored CVEs.
- Low exploitation riskCVE-2026-106990.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-119030.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-10698 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-10699 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-11903 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in Progress MOVEit Transfer (July 10, 2026)cert-fr-avis
- high[NEW] [high] Progress Software MOVEit: Multiple vulnerabilitiescert-bund
- criticalProgress security advisory (AV26-678)cccs
- highCVE-2026-11903: Improper neutralization of input during web page generation ('cross-site scripting') vulnerabi…nvd
- highCVE-2026-10699: Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (…nvd
- highCVE-2026-10698: Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVE…nvd
Recent advisories for Progress MOVEit Transfer
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)cert-fr-avis · 2026-07-31
- medium[NEW] [medium] Progress Software MOVEit Transfer: Multiple vulnerabilitiescert-bund · 2026-07-24
- highCVE-2026-15968: Improper neutralization of input during web page generation ('cross-site scripting') vulnerabi…nvd · 2026-07-23
- highCVE-2026-15967: Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects …nvd · 2026-07-23
- highCVE-2026-15966: Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEi…nvd · 2026-07-23
- highCVE-2026-10697: Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit T…nvd · 2026-07-23
More from NCSC-NL Advisories
- unknownNCSC-2026-0268 [1.01] [M/H] Kwetsbaarheid verholpen in SQLite door SQLite Consortium (ingetrokken)2026-08-03
- unknownNCSC-2026-0275 [1.00] [M/H] Kwetsbaarheden verholpen in N-able N-central2026-08-03
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31