Progress Security Update – 09 July 2026

Progress Software Corporation has released a security update to fix multiple vulnerabilities affecting MOVEit transfer.

The addressed vulnerabilities could allow the attacker to bypass security restrictions or perform cross-site scripting and denial-of-service attacks on the affected systems.

Sample of the addressed vulnerabilities:

1. Progress MOVEit Transfer Improper Neutralization of Input During Web Page Generation (XSS) Vulnerability (CVE-2026-11903):

  • CVSS: 8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: Required
  • Consequences: Cross-Site Scripting

2. Progress MOVEit Transfer Missing Release of Memory After Effective Lifetime Vulnerability (CVE-2026-10699):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service
Vulnerabilities
  • CVE-2026-10699
  • CVE-2026-10698
  • CVE-2026-11903
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Progress Security Advisory

References