Skip to content
Progress SoftwareCVE-2026-10698

Improper Neutralization of Special Elements in Data Query Logic vulnerability...

High7.2CVE-2026-10698 · Published Jul 8, 2026 · updated Jul 10, 2026

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1.

Progress Software advisory

Affected versions

PackageAffectedFixed in
MOVEit Transfer
Product
>= 2025.0.0, < 2025.0.82025.0.8
>= 2025.1.0, < 2025.1.42025.1.4
>= 2026.0.0, < 2026.0.12026.0.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-943

More Progress Software advisories

All Progress Software
Advisory
Path equivalence: vulnerability in Progress MOVEit Transfer
Low3.5Jul 8
Improper Neutralization of Special Elements in Data Query Logic vulnerability...
Medium6.4Jul 8
Progress Software MOVEit Transfer: path traversal
Medium4.5Jul 8
Progress Software MOVEit Transfer: authentication bypass
Low3.7Jul 8
Progress Software MOVEit Transfer: improper authorization
Low2.7Jul 8
Progress Software MOVEit Transfer: memory leak
High7.5Jul 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.