PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10697 Progress CVE debrief

CVE-2026-10697 is an Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. According to the CVE record, the vulnerability has a CVSS score of 7.5 and a severity of HIGH. The vulnerability could allow an attacker to gain unauthorized access to the system, potentially leading to data breaches or system compromise. Security teams should review the CVE record and assess their MOVEit Transfer installations for potential exposure.

Vendor
Progress
Product
MOVEit Transfer
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-23
Original CVE updated
2026-07-25
Advisory published
2026-07-23
Advisory updated
2026-07-25

Who should care

Security teams and administrators responsible for Progress MOVEit Transfer installations should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing the CVE record, assessing their installations for potential exposure, and implementing patches or updates as needed. Additionally, operators and platform administrators should be informed of the potential risks and take steps to verify authentication mechanisms and implement compensating controls.

Technical summary

The vulnerability is caused by improper authentication in Progress MOVEit Transfer. This could allow an attacker to gain unauthorized access to the system. The affected versions are before 2025.1.5 and from 2026.0.0 before 2026.0.3. The vulnerability has a CVSS score of 7.5 and a severity of HIGH, indicating a significant risk to affected systems. To mitigate this risk, administrators should ensure that authentication mechanisms are properly configured and consider implementing compensating controls.

Defensive priority

High

Recommended defensive actions

  • Inventory and assess Progress MOVEit Transfer installations for vulnerability
  • Apply patches or updates to affected versions
  • Implement compensating controls, such as monitoring and access restrictions
  • Verify authentication mechanisms are properly configured
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD detail provide information on the vulnerability. However, further investigation is needed to determine the full scope of the vulnerability and affected systems. The CVE record was published on 2026-07-23T21:17:01.597Z and has not been modified since then. The source item URL and other references may provide additional context for understanding the vulnerability.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T21:17:01.597Z and has not been modified since then.