FAIL › dossier
moveit transfer
PRODUCT· dossier confidence 50%
Progress MOVEit Transfer is a data transfer platform with a documented history of severe security flaws, including a ransomware-linked breach via SQL injection and multiple high-severity vulnerabilities in authentication and session management. Its security posture is compromised by repeated critical and high-severity flaws that affect older versions, requiring urgent patching and version upgrades.
PROFILE
CategoryData Transfer SoftwareWhat they doProgress MOVEit Transfer is a data transfer and management platform used for secure file transfers between systems.
SECURITY POSTURE
Progress MOVEit Transfer has a poor security track record, with multiple critical and high-severity vulnerabilities exploited in the wild, including a ransomware-linked breach via SQL injection.
Notable failures
- CVE-2023-34362: Unauthenticated SQL injection leading to ransomware breach
- CVE-2026-10697: Improper authentication vulnerability
- CVE-2026-15967: Insufficient session expiration vulnerability
Patterns: Repeated critical and high-severity vulnerabilities in core modules (SQL injection, authentication, session management); Vulnerabilities affecting versions prior to 2025.0.8 and 2025.1.4
FAILURE HISTORY · 6
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2023-06-02 | CVE-2023-34362 | critical | An unauthenticated SQL injection flaw in Progress MOVEit Transfer allowed attackers to alter or delete database elements, leading to a ransomware-linked breach. |
| 2026-07-08 | CVE-2026-8801 | low | Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4. |
| 2026-07-08 | CVE-2026-8649 | medium | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. |
| 2026-07-23 | CVE-2026-10697 | high | CVE-2026-10697: Improper Authentication vulnerability in Progress MOVEit Transfer. This issue a |
| 2026-07-23 | CVE-2026-15967 | high | CVE-2026-15967: Insufficient session expiration vulnerability in Progress MOVEit Transfer. This |
| 2026-07-23 | CVE-2026-15966 | high | CVE-2026-15966: Permissive cross-domain security policy with untrusted domains vulnerability in |
Open questions: Exact founding year and headquarters location of Progress MOVEit Transfer · Current ownership structure of Progress MOVEit Transfer · Total number of employees at Progress MOVEit Transfer
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-25 03:49:37.692428+00:00