PatchSiren cyber security CVE debrief
CVE-2026-10697 Progress CVE debrief
CVE-2026-10697 is an Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. According to the CVE record, the vulnerability has a CVSS score of 7.5 and a severity of HIGH. The vulnerability could allow an attacker to gain unauthorized access to the system, potentially leading to data breaches or system compromise. Security teams should review the CVE record and assess their MOVEit Transfer installations for potential exposure.
- Vendor
- Progress
- Product
- MOVEit Transfer
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-23
- Original CVE updated
- 2026-07-25
- Advisory published
- 2026-07-23
- Advisory updated
- 2026-07-25
Who should care
Security teams and administrators responsible for Progress MOVEit Transfer installations should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing the CVE record, assessing their installations for potential exposure, and implementing patches or updates as needed. Additionally, operators and platform administrators should be informed of the potential risks and take steps to verify authentication mechanisms and implement compensating controls.
Technical summary
The vulnerability is caused by improper authentication in Progress MOVEit Transfer. This could allow an attacker to gain unauthorized access to the system. The affected versions are before 2025.1.5 and from 2026.0.0 before 2026.0.3. The vulnerability has a CVSS score of 7.5 and a severity of HIGH, indicating a significant risk to affected systems. To mitigate this risk, administrators should ensure that authentication mechanisms are properly configured and consider implementing compensating controls.
Defensive priority
High
Recommended defensive actions
- Inventory and assess Progress MOVEit Transfer installations for vulnerability
- Apply patches or updates to affected versions
- Implement compensating controls, such as monitoring and access restrictions
- Verify authentication mechanisms are properly configured
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD detail provide information on the vulnerability. However, further investigation is needed to determine the full scope of the vulnerability and affected systems. The CVE record was published on 2026-07-23T21:17:01.597Z and has not been modified since then. The source item URL and other references may provide additional context for understanding the vulnerability.
Official resources
-
CVE-2026-10697 CVE record
CVE.org
-
CVE-2026-10697 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T21:17:01.597Z and has not been modified since then.