Cross-Site Scripting Vulnerability in MOVEit Transfer by Progress
CVE-2026-15968

7.1HIGH

Key Information:

Vendor

Progress

Vendor
CVE Published:
23 July 2026

What is CVE-2026-15968?

A cross-site scripting vulnerability exists in Progress MOVEit Transfer, where improper neutralization of input during web page generation could allow an attacker to inject malicious scripts into web pages viewed by users. This vulnerability affects versions before 2025.1.5 and between 2026.0.0 and 2026.0.3, potentially leading to unauthorized actions on behalf of users and compromise of sensitive information.

Affected Version(s)

MOVEit Transfer 0 < 2025.1.5

MOVEit Transfer 2026.0.0 < 2026.0.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.