Skip to content
Progress SoftwareCVE-2026-15966

Permissive cross-domain security policy with untrusted domains vulnerability in...

High7.5CVE-2026-15966 · Published Jul 23, 2026 · updated Jul 30, 2026

Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

Progress Software advisory

Affected versions

PackageAffectedFixed in
MOVEit Transfer
Product
< 2025.1.52025.1.5
>= 2026.0.0, < 2026.0.32026.0.3
Details and references

More Progress Software advisories

All Progress Software
Advisory
Progress Software MOVEit Transfer: cross-site scripting
High7.1Jul 23
Progress Software MOVEit Transfer: insufficient session expiration
High7.5Jul 23
Progress Software MOVEit Transfer: improper authentication
High7.5Jul 23
Progress Software Telerik UI for ASP.NET AJAX: denial of service
Medium5.3Jul 22
Progress Software Telerik UI for ASP.NET AJAX: hard-coded key
Medium6.5Jul 22
Progress Software Telerik UI for ASP.NET AJAX: remote code execution
High8.1Jul 22

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.