Spoofing Vulnerability in Progress MOVEit Transfer Software
CVE-2026-8651

3.7LOW

Key Information:

Vendor

Progress

Vendor
CVE Published:
8 July 2026

What is CVE-2026-8651?

A spoofing vulnerability exists in Progress MOVEit Transfer's HTTPS module, potentially allowing attackers to bypass authentication limitations. This issue affects versions of MOVEit Transfer released before 2025.0.7 and from version 2025.1.0 up to, but not including, 2025.1.3. Users are advised to update to the latest versions to mitigate potential risks.

Affected Version(s)

MOVEit Transfer 2025.1.0 < 2025.1.3

MOVEit Transfer 0 < 2025.0.7

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Niv Levy
.