# MOVEit Transfer patches XSS, bypass flaws

Published: 2026-07-31 · Severity: medium
Canonical: https://vorant.io/reports/ec6f6ddb-55a1-52ae-8284-9cac12d5dcea/moveit-transfer-patches-xss-bypass-flaws

> Progress patched multiple MOVEit Transfer vulnerabilities allowing remote XSS injection and security policy bypass, fixed in version 2026.0.3.

CERT-FR issued an advisory covering multiple vulnerabilities discovered in Progress MOVEit Transfer affecting all versions prior to 2026.0.3. The flaws allow an attacker to perform indirect remote code injection (cross-site scripting) and bypass security policy controls. Four CVEs were assigned to this set of vulnerabilities: CVE-2026-10697, CVE-2026-15966, CVE-2026-15967, and CVE-2026-15968.

Progress released a security bulletin on July 24, 2026 alongside version 2026.0.3, which contains fixes for the identified issues. No exploitation in the wild is mentioned in this advisory. Organizations running affected MOVEit Transfer deployments should apply the vendor patch as described in the referenced documentation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-10697, CVE-2026-15966, CVE-2026-15967, CVE-2026-15968

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0951

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ec6f6ddb-55a1-52ae-8284-9cac12d5dcea/moveit-transfer-patches-xss-bypass-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
