VORANT. Threat Intelligence Sign in Get the full feed

Progress MOVEit WAF Patches Five Critical CVEs

routine vulnerability technology

ANSSI advisory details five vulnerabilities in Progress MOVEit WAF allowing remote code execution, privilege escalation, and security bypass.

The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory covering five newly disclosed vulnerabilities in Progress MOVEit WAF versions prior to 7.2.63.3. The flaws, tracked as CVE-2026-59686 through CVE-2026-59690, can allow an attacker to bypass security policy protections, execute arbitrary code remotely, and escalate privileges on affected systems.

Progress published a corresponding vendor security bulletin on 24 July 2026 detailing the issues and providing patched versions. No evidence of active exploitation is mentioned in the advisory; organizations running MOVEit WAF are advised to apply the vendor's fixes promptly given the product's role as a security gateway protecting managed file transfer infrastructure.

Mentioned in this report

Vulnerabilities CVE-2026-59686CVE-2026-59687CVE-2026-59688CVE-2026-59689CVE-2026-59690

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1011

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free