PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10697 Progress CVE debrief

CVE-2026-10697 is an Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. According to the CVE record, the vulnerability has a CVSS score of 7.5 and a severity of HIGH. The vulnerability could allow an attacker to gain unauthorized access to the system, potentially leading to data breaches or system compromise. Security teams should review the CVE record and assess their MOVEit Transfer installations for potential exposure.

Vendor
Progress
Product
MOVEit Transfer
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-23
Original CVE updated
2026-07-28
Advisory published
2026-07-23
Advisory updated
2026-07-28

Who should care

Security teams and administrators responsible for Progress MOVEit Transfer installations should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing the CVE record, assessing their installations for potential exposure, and implementing patches or updates as needed. Additionally, operators and platform administrators should be informed of the potential risks and take steps to verify authentication mechanisms and implement compensating controls.

Technical summary

The vulnerability is caused by improper authentication in Progress MOVEit Transfer. This could allow an attacker to gain unauthorized access to the system. The affected versions are before 2025.1.5 and from 2026.0.0 before 2026.0.3. The vulnerability has a CVSS score of 7.5 and a severity of HIGH, indicating a significant risk to affected systems. To mitigate this risk, administrators should ensure that authentication mechanisms are properly configured and consider implementing compensating controls.

Defensive priority

High

Recommended defensive actions

  • Inventory and assess Progress MOVEit Transfer installations for vulnerability
  • Apply patches or updates to affected versions
  • Implement compensating controls, such as monitoring and access restrictions
  • Verify authentication mechanisms are properly configured
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD detail provide information on the vulnerability. However, further investigation is needed to determine the full scope of the vulnerability and affected systems. The CVE record was published on 2026-07-23T21:17:01.597Z and has not been modified since then. The source item URL and other references may provide additional context for understanding the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-10697 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-10697

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-10697 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10697

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.0.3.html

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.