Junglewise Threat Intelligence

CVE-2026-10699: Progress MOVEit Transfer memory leak in Custom Reports modules

CVE-2026-10699 · Severity: high · CVSS 7.5 · Published 2026-07-08

Technologies: Progress MOVEit Transfer. Vendors: Progress.

Executive brief

Progress MOVEit Transfer, a managed file transfer solution used by organizations to securely share sensitive data, contains a vulnerability in its Custom Reports modules. An attacker could exploit this flaw to cause a denial-of-service condition by exhausting system memory. This could lead to service instability or complete outages, preventing legitimate users from accessing or transferring files.

Technical details

A 'Missing Release of Memory after Effective Lifetime' (CWE-401) vulnerability exists in the Custom Reports modules of Progress MOVEit Transfer. The flaw allows a remote attacker to trigger memory exhaustion on the host system without requiring authentication. By repeatedly invoking specific reporting functions that fail to release memory, an attacker can consume available resources until the service becomes unresponsive or crashes. The issue is fixed in versions 2025.0.8, 2025.1.4, and 2026.0.1.

Affected products

  • Progress MOVEit Transfer 2025.0.0 before 2025.0.8, 2025.1.0 before 2025.1.4, 2026.0.0 before 2026.0.1

Timeline

  • 2026-07-08: advisory: NVD and vendor advisory published

References

Related threats