Progress security advisory (AV26-746)
Serial number: AV26-746 Date: July 24, 2026 On July 23, 2026, Progress published security advisories to address vulnerabilities in the following product: MOVEit Transfer – versions prior to 2025.1.5 MOVEit Transfer – versions prior to 2026.0.3 The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. MOVEit Transfer 2026 Release Notes - Fixed Issues in 2026.0.3 Progress Trust Center
CSIRTS triage
- What
- There are vulnerabilities in MOVEit Transfer that need to be addressed.
- Who is affected
- Users and administrators of MOVEit Transfer versions prior to 2025.1.5 and 2026.0.3 are affected.
- Urgency
- Remediation is necessary to ensure security, although exploitation status is currently unknown.
- Action
- Users should apply the necessary updates to the specified versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch MOVEit Transfer
Get an email when a new MOVEit Transfer advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/progress-security-advisory-av26-746
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30