{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/moveit-transfer/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-10697"},{"cvss":7.5,"id":"CVE-2026-15966"},{"cvss":7.5,"id":"CVE-2026-15967"},{"cvss":7.1,"id":"CVE-2026-15968"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MOVEit Transfer"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","moveit"],"_cs_type":"advisory","_cs_vendors":["Progress"],"content_html":"\u003cp\u003eProgress has disclosed multiple critical vulnerabilities affecting MOVEit Transfer versions prior to 2026.0.3. These vulnerabilities, identified as CVE-2026-10697, CVE-2026-15966, CVE-2026-15967, and CVE-2026-15968, allow remote attackers to perform indirect cross-site scripting (XSS) attacks and bypass established security policies. These flaws reside within the application's web interface handling and security control logic. Successful exploitation can lead to unauthorized access, session hijacking, or the execution of malicious scripts within the context of a legitimate user session. Given the role of MOVEit as a managed file transfer solution, these vulnerabilities pose a significant risk to data integrity and confidentiality for organizations handling sensitive information.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows remote, unauthenticated or authenticated attackers to bypass security controls or execute arbitrary scripts in the victim's browser session. Potential consequences include unauthorized data exfiltration, account takeover, and persistent unauthorized access to the file transfer platform. These vulnerabilities affect all instances of MOVEit Transfer running versions earlier than 2026.0.3.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all MOVEit Transfer instances to version 2026.0.3 or later immediately, as documented in the Progress security bulletin.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous patterns such as injected script tags or unusual parameters in requests directed at the MOVEit Transfer web portal.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized configuration changes or security policy modifications within the MOVEit administrative console.\u003c/li\u003e\n\u003cli\u003eRestrict access to the MOVEit Transfer web interface to trusted IP ranges to limit the attack surface while the upgrade is being deployed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-31T15:28:24Z","date_published":"2026-07-31T15:28:24Z","id":"https://feed.craftedsignal.io/briefs/2026-07-moveit-vulnerabilities/","summary":"Multiple vulnerabilities, including remote XSS and security policy bypass, have been identified in Progress MOVEit Transfer versions prior to 2026.0.3, enabling potential unauthorized access and session-based script execution.","title":"Multiple Vulnerabilities in Progress MOVEit Transfer","url":"https://feed.craftedsignal.io/briefs/2026-07-moveit-vulnerabilities/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MOVEit Transfer"],"_cs_severities":["high"],"_cs_tags":["vulnerability","moveit","file-transfer","data-exfiltration","privilege-escalation","web-application"],"_cs_type":"threat","_cs_vendors":["Progress Software"],"content_html":"\u003cp\u003eThe German Federal Office for Information Security (BSI) has issued an advisory regarding multiple vulnerabilities identified in Progress Software's MOVEit Transfer solution. These security flaws could enable an attacker to circumvent existing security measures, escalate their privileges within the system, tamper with data, or expose sensitive information. Additionally, the vulnerabilities could facilitate Cross-Site-Scripting (XSS) attacks. While the advisory does not specify if these vulnerabilities are currently under active exploitation, their presence in a widely used managed file transfer product like MOVEit Transfer poses a significant risk to organizations that rely on the platform for secure data exchange. Defenders should prioritize patching to mitigate potential compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could lead to significant unauthorized access to confidential or sensitive data, integrity compromise through data manipulation, and full system compromise due to privilege escalation. Organizations using MOVEit Transfer for regulated data or critical business processes face potential data breaches, operational disruptions, financial penalties, and reputational damage. The absence of specific observed exploitation details or CVEs in this advisory means the exact scope of immediate threat is unclear, but the potential consequences of these vulnerability types are severe, echoing past incidents involving the MOVEit platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply all available security updates and patches from Progress Software for MOVEit Transfer immediately.\u003c/li\u003e\n\u003cli\u003eMonitor MOVEit Transfer logs for indicators of unauthorized access, privilege escalation attempts, data modification, or unusual data exfiltration activity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T11:25:04Z","date_published":"2026-07-24T11:25:04Z","id":"https://feed.craftedsignal.io/briefs/2026-07-multiple-moveit-transfer-vulnerabilities/","summary":"Multiple vulnerabilities in Progress Software MOVEit Transfer allow attackers to bypass security measures, achieve elevated privileges, and manipulate or disclose sensitive data, including the ability to perform Cross-Site-Scripting (XSS) attacks.","title":"Multiple Vulnerabilities in Progress Software MOVEit Transfer","url":"https://feed.craftedsignal.io/briefs/2026-07-multiple-moveit-transfer-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - MOVEit Transfer","version":"https://jsonfeed.org/version/1.1"}