CVE-2026-15968
- EPSS 0.18%
- Veröffentlicht 23.07.2026 20:01:13
- Zuletzt bearbeitet 30.07.2026 15:49:28
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
CVE-2026-15967
- EPSS 0.2%
- Veröffentlicht 23.07.2026 19:59:33
- Zuletzt bearbeitet 30.07.2026 15:50:12
Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
CVE-2026-15966
- EPSS 0.2%
- Veröffentlicht 23.07.2026 19:58:01
- Zuletzt bearbeitet 30.07.2026 15:50:24
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
CVE-2026-10697
- EPSS 0.29%
- Veröffentlicht 23.07.2026 19:54:48
- Zuletzt bearbeitet 30.07.2026 15:50:34
Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
CVE-2026-8801
- EPSS 0.35%
- Veröffentlicht 08.07.2026 20:17:01
- Zuletzt bearbeitet 09.07.2026 19:16:37
Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
CVE-2026-8650
- EPSS 0.2%
- Veröffentlicht 08.07.2026 20:17:00
- Zuletzt bearbeitet 09.07.2026 19:18:57
Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
CVE-2026-8651
- EPSS 0.22%
- Veröffentlicht 08.07.2026 20:17:00
- Zuletzt bearbeitet 09.07.2026 19:18:09
Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
CVE-2026-8800
- EPSS 0.21%
- Veröffentlicht 08.07.2026 20:17:00
- Zuletzt bearbeitet 09.07.2026 19:17:34
Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
CVE-2026-8649
- EPSS 0.26%
- Veröffentlicht 08.07.2026 19:41:40
- Zuletzt bearbeitet 10.07.2026 19:34:37
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
CVE-2026-10699
- EPSS 0.34%
- Veröffentlicht 08.07.2026 14:18:00
- Zuletzt bearbeitet 10.07.2026 14:25:58
Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1.