VORANT. Threat Intelligence Sign in Get the full feed

MOVEit Transfer patches XSS, bypass flaws

medium vulnerability

Progress patched multiple MOVEit Transfer vulnerabilities allowing remote XSS injection and security policy bypass, fixed in version 2026.0.3.

CERT-FR issued an advisory covering multiple vulnerabilities discovered in Progress MOVEit Transfer affecting all versions prior to 2026.0.3. The flaws allow an attacker to perform indirect remote code injection (cross-site scripting) and bypass security policy controls. Four CVEs were assigned to this set of vulnerabilities: CVE-2026-10697, CVE-2026-15966, CVE-2026-15967, and CVE-2026-15968.

Progress released a security bulletin on July 24, 2026 alongside version 2026.0.3, which contains fixes for the identified issues. No exploitation in the wild is mentioned in this advisory. Organizations running affected MOVEit Transfer deployments should apply the vendor patch as described in the referenced documentation.

Mentioned in this report

Vulnerabilities CVE-2026-10697CVE-2026-15966CVE-2026-15967CVE-2026-15968

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0951

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free