Junglewise Threat Intelligence

CVE-2026-10697: Progress MOVEit Transfer improper authentication

CVE-2026-10697 · Severity: high · CVSS 7.5 · Published 2026-07-23

Technologies: Progress MOVEit Transfer. Vendors: Progress.

Executive brief

Progress MOVEit Transfer, a widely used managed file transfer solution for securely sharing sensitive business data, contains a security flaw in its authentication process. An attacker could potentially bypass security checks to gain unauthorized access to the system, leading to the theft of sensitive files or disruption of file transfer operations. Organizations should update to the latest patched versions to protect their data and maintain regulatory compliance.

Technical details

An improper authentication vulnerability (CWE-287) exists in Progress MOVEit Transfer. The flaw allows an attacker on the adjacent network to potentially bypass authentication mechanisms under specific high-complexity conditions. If successfully exploited, this could lead to a complete compromise of confidentiality, integrity, and availability of the file transfer service. The issue affects versions prior to 2025.1.5 and the 2026.0.x branch prior to 2026.0.3. Progress has released patches to address this vulnerability.

Affected products

  • Progress MOVEit Transfer before 2025.1.5, 2026.0.0 before 2026.0.3

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References

Related threats