MOVEit Transfer
Progress- Product type
- Other
- Catalog vulnerabilities
- 18
Severity across 18 analyzed records
Verify to analyze this security profile
en
As of 09/29/2026, within CyStack's analyzed data, MOVEit Transfer has 12 security vulnerabilities published in the last 90 days. Of these, 7 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of MOVEit Transfer and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-15968Stored XSS vulnerability in MOVEit Transfer | Exploitation statusNot known exploited | FixYes | Published07/23/2026 | SeverityHigh |
CVE-2026-15967MOVEit Transfer refresh-token processing does not enforce updated account restrictions | Exploitation statusNot known exploited | FixYes | Published07/23/2026 | SeverityHigh |
CVE-2026-15966Improper CORS handling in MOVEit Transfer | Exploitation statusNot known exploited | FixYes | Published07/23/2026 | SeverityHigh |
CVE-2026-10697MFA Bypass in MOVEit Transfer | Exploitation statusNot known exploited | FixYes | Published07/23/2026 | SeverityHigh |
CVE-2026-8801File Extension Restriction Bypass in MOVEit Transfer | Exploitation statusNot known exploited | FixYes | Published07/08/2026 | SeverityLow |
CVE-2026-8800Cross-Org External Token Metadata accessible to AuditUser role | Exploitation statusNot known exploited | FixYes | Published07/08/2026 | SeverityLow |
CVE-2026-8651IPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit Transfer | Exploitation statusNot known exploited | FixYes | Published07/08/2026 | SeverityLow |
CVE-2026-8650Authenticated Path Traversal allows MOVEit admins to view arbitrary system files | Exploitation statusNot known exploited | FixYes | Published07/08/2026 | SeverityMedium |
CVE-2026-8649Institution scope bypass vulnerability in custom reports | Exploitation statusNot known exploited | FixYes | Published07/08/2026 | SeverityMedium |
CVE-2026-11903Stored XSS in MOVEit Transfer Ad Hoc module | Exploitation statusNot known exploited | FixYes | Published07/08/2026 | SeverityHigh |
CVE-2026-10699Memory leak in SFTP service can result in a denial of service in MOVEit Transfer | Exploitation statusNot known exploited | FixYes | Published07/08/2026 | SeverityHigh |
CVE-2026-10698Table scope bypass vulnerability in custom reports | Exploitation statusNot known exploited | FixYes | Published07/08/2026 | SeverityHigh |
CVE-2025-11235MOVEit Transfer REST API does not require current password in order to initiate the password change process | Exploitation statusNot known exploited | FixYes | Published01/06/2026 | SeverityLow |
CVE-2025-13147External Service Interaction (DNS) | Exploitation statusNot known exploited | FixYes | Published11/19/2025 | SeverityMedium |
CVE-2025-10932AS2 module allows uncontrolled file uploads | Exploitation statusNot known exploited | FixYes | Published10/29/2025 | SeverityHigh |
CVE-2025-2324A MOVEit Transfer user configured as a Shared Account can gain unintended List permissions on a folder | Exploitation statusNot known exploited | FixYes | Published03/19/2025 | SeverityMedium |
CVE-2024-6576MOVEit Transfer Privilege Escalation Vulnerability | Exploitation statusNot known exploited | FixYes | Published07/29/2024 | SeverityHigh |
CVE-2024-5806MOVEit Transfer Authentication Bypass Vulnerability | Exploitation statusPublic exploit | FixYes | Published06/25/2024 | SeverityCritical |