{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aprogressmoveit_transfer/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-10697"},{"cvss":7.5,"id":"CVE-2026-15966"},{"cvss":7.5,"id":"CVE-2026-15967"},{"cvss":7.1,"id":"CVE-2026-15968"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MOVEit Transfer"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","moveit"],"_cs_type":"advisory","_cs_vendors":["Progress"],"content_html":"\u003cp\u003eProgress has disclosed multiple critical vulnerabilities affecting MOVEit Transfer versions prior to 2026.0.3. These vulnerabilities, identified as CVE-2026-10697, CVE-2026-15966, CVE-2026-15967, and CVE-2026-15968, allow remote attackers to perform indirect cross-site scripting (XSS) attacks and bypass established security policies. These flaws reside within the application's web interface handling and security control logic. Successful exploitation can lead to unauthorized access, session hijacking, or the execution of malicious scripts within the context of a legitimate user session. Given the role of MOVEit as a managed file transfer solution, these vulnerabilities pose a significant risk to data integrity and confidentiality for organizations handling sensitive information.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows remote, unauthenticated or authenticated attackers to bypass security controls or execute arbitrary scripts in the victim's browser session. Potential consequences include unauthorized data exfiltration, account takeover, and persistent unauthorized access to the file transfer platform. These vulnerabilities affect all instances of MOVEit Transfer running versions earlier than 2026.0.3.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all MOVEit Transfer instances to version 2026.0.3 or later immediately, as documented in the Progress security bulletin.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous patterns such as injected script tags or unusual parameters in requests directed at the MOVEit Transfer web portal.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized configuration changes or security policy modifications within the MOVEit administrative console.\u003c/li\u003e\n\u003cli\u003eRestrict access to the MOVEit Transfer web interface to trusted IP ranges to limit the attack surface while the upgrade is being deployed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-31T15:28:24Z","date_published":"2026-07-31T15:28:24Z","id":"https://feed.craftedsignal.io/briefs/2026-07-moveit-vulnerabilities/","summary":"Multiple vulnerabilities, including remote XSS and security policy bypass, have been identified in Progress MOVEit Transfer versions prior to 2026.0.3, enabling potential unauthorized access and session-based script execution.","title":"Multiple Vulnerabilities in Progress MOVEit Transfer","url":"https://feed.craftedsignal.io/briefs/2026-07-moveit-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}