Skip to content
Progress SoftwareCVE-2026-8651

Progress Software MOVEit Transfer: authentication bypass

Low3.7CVE-2026-8651 · Published Jul 8, 2026 · updated Jul 9, 2026

Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Progress Software advisory

Affected versions

PackageAffectedFixed in
MOVEit Transfer
Product
>= 2025.1.0, < 2025.1.32025.1.3
< 2025.0.72025.0.7
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-290

More Progress Software advisories

All Progress Software
Advisory
Path equivalence: vulnerability in Progress MOVEit Transfer
Low3.5Jul 8
Improper Neutralization of Special Elements in Data Query Logic vulnerability...
Medium6.4Jul 8
Progress Software MOVEit Transfer: path traversal
Medium4.5Jul 8
Progress Software MOVEit Transfer: improper authorization
Low2.7Jul 8
Improper Neutralization of Special Elements in Data Query Logic vulnerability...
High7.2Jul 8
Progress Software MOVEit Transfer: memory leak
High7.5Jul 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.