Multiple vulnerabilities in Progress MOVEit Transfer versions prior to 2026.0.3 enable attackers to exploit cross-site scripting (XSS) and bypass security policies. The vulnerabilities, detailed in a security bulletin released on July 24, 2026, pose risks of remote code injection and policy circumvention. Affected systems are advised to apply updates from Progress’ security bulletin. Four CVE identifiers are linked to the issues: CVE-2026-10697, CVE-2026-15966, CVE-2026-15967, and CVE-2026-15968. The CERT-FR advisory, published on July 31, 2026, underscores the need for immediate patching to mitigate potential security breaches.
Summary of content from
Made by AI. If you spot anything of concern write us at contact@cybach.com. We’ll promptly correct irregularities.