Skip to content
COOEY

FAIL › dossier

moveit transfer

PRODUCT

· dossier confidence 50%

Progress MOVEit Transfer is a data transfer platform with a documented history of severe security flaws, including a ransomware-linked breach via SQL injection and multiple high-severity vulnerabilities in authentication and session management. Its security posture is compromised by repeated critical and high-severity flaws that affect older versions, requiring urgent patching and version upgrades.

PROFILE
CategoryData Transfer SoftwareWhat they doProgress MOVEit Transfer is a data transfer and management platform used for secure file transfers between systems.
SECURITY POSTURE

Progress MOVEit Transfer has a poor security track record, with multiple critical and high-severity vulnerabilities exploited in the wild, including a ransomware-linked breach via SQL injection.

Notable failures
  • CVE-2023-34362: Unauthenticated SQL injection leading to ransomware breach
  • CVE-2026-10697: Improper authentication vulnerability
  • CVE-2026-15967: Insufficient session expiration vulnerability
Patterns: Repeated critical and high-severity vulnerabilities in core modules (SQL injection, authentication, session management); Vulnerabilities affecting versions prior to 2025.0.8 and 2025.1.4
FAILURE HISTORY · 6
DATEEVENTSEVSUMMARY
2023-06-02 CVE-2023-34362 critical An unauthenticated SQL injection flaw in Progress MOVEit Transfer allowed attackers to alter or delete database elements, leading to a ransomware-linked breach.
2026-07-08 CVE-2026-8801 low Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
2026-07-08 CVE-2026-8649 medium Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
2026-07-23 CVE-2026-10697 high CVE-2026-10697: Improper Authentication vulnerability in Progress MOVEit Transfer. This issue a
2026-07-23 CVE-2026-15967 high CVE-2026-15967: Insufficient session expiration vulnerability in Progress MOVEit Transfer. This
2026-07-23 CVE-2026-15966 high CVE-2026-15966: Permissive cross-domain security policy with untrusted domains vulnerability in
Open questions: Exact founding year and headquarters location of Progress MOVEit Transfer · Current ownership structure of Progress MOVEit Transfer · Total number of employees at Progress MOVEit Transfer
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-25 03:49:37.692428+00:00