# Progress MOVEit WAF Patches Five Critical CVEs

Published: 2026-08-13 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/379e1d8d-f8cd-5b40-823a-ed65d6b70859/progress-moveit-waf-patches-five-critical-cves

> ANSSI advisory details five vulnerabilities in Progress MOVEit WAF allowing remote code execution, privilege escalation, and security bypass.

The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory covering five newly disclosed vulnerabilities in Progress MOVEit WAF versions prior to 7.2.63.3. The flaws, tracked as CVE-2026-59686 through CVE-2026-59690, can allow an attacker to bypass security policy protections, execute arbitrary code remotely, and escalate privileges on affected systems.

Progress published a corresponding vendor security bulletin on 24 July 2026 detailing the issues and providing patched versions. No evidence of active exploitation is mentioned in the advisory; organizations running MOVEit WAF are advised to apply the vendor's fixes promptly given the product's role as a security gateway protecting managed file transfer infrastructure.

## Mentioned in this report

- Vulnerabilities: CVE-2026-59686, CVE-2026-59687, CVE-2026-59688, CVE-2026-59689, CVE-2026-59690

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1011

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/379e1d8d-f8cd-5b40-823a-ed65d6b70859/progress-moveit-waf-patches-five-critical-cves.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
