Cross-Site Scripting Vulnerability in MOVEit Transfer by Progress
CVE-2026-15968
7.1HIGH
What is CVE-2026-15968?
A cross-site scripting vulnerability exists in Progress MOVEit Transfer, where improper neutralization of input during web page generation could allow an attacker to inject malicious scripts into web pages viewed by users. This vulnerability affects versions before 2025.1.5 and between 2026.0.0 and 2026.0.3, potentially leading to unauthorized actions on behalf of users and compromise of sensitive information.
Affected Version(s)
MOVEit Transfer 0 < 2025.1.5
MOVEit Transfer 2026.0.0 < 2026.0.3
