Junglewise Threat Intelligence

CVE-2026-15968: Progress MOVEit Transfer cross-site scripting in Find File page

CVE-2026-15968 · Severity: high · CVSS 7.1 · Published 2026-07-23

Technologies: Progress MOVEit Transfer. Vendors: Progress.

Executive brief

Progress MOVEit Transfer, a managed file transfer solution used by organizations to securely share sensitive data, is vulnerable to a cross-site scripting (XSS) attack. An attacker could potentially execute malicious scripts in the browser of a legitimate user, which could lead to the theft of session cookies or unauthorized actions performed on behalf of that user. This issue specifically impacts the 'Find File' page within the web interface.

Technical details

A stored or reflected cross-site scripting (XSS) vulnerability exists in the 'Find File' page of Progress MOVEit Transfer due to improper neutralization of input during web page generation. An attacker with low-level privileges (PR:L) can exploit this by injecting malicious scripts that are executed when a victim interacts with the affected page (UI:R). While the attack complexity is rated as high (AC:H), a successful exploit could allow the attacker to compromise the confidentiality, integrity, and availability of the user's session. The vulnerability is addressed in versions 2025.1.5 and 2026.0.3.

Affected products

  • Progress MOVEit Transfer before 2025.1.5, 2026.0.0 before 2026.0.3

Timeline

  • 2026-07-22: patched: Release of MOVEit Transfer 2026.0.3 Service Pack
  • 2026-07-23: disclosed: CVE published by Progress Software Corporation

References

Related threats