Progress Software released security updates for multiple vulnerabilities in MOVEit Transfer that could allow security-restriction bypass, cross-site scripting (XSS), and denial-of-service attacks against affected deployments. The issues include CVE-2026-11903, an authenticated, low-complexity network XSS flaw rated CVSS 8.0, and CVE-2026-10699, an unauthenticated, low-complexity network denial-of-service vulnerability rated CVSS 7.5.
Organizations using MOVEit Transfer should test and deploy the available updates promptly. Priority should be given to internet-facing instances, with administrators validating patch installation and monitoring application and network logs for suspicious activity or service-disruption attempts.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Progress Software Corporation released an update for MOVEit Transfer addressing CVE-2026-10698, CVE-2026-10699, and CVE-2026-11903. The flaws could permit security-restriction bypass, cross-site scripting, or denial-of-service attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.