NCSC-2026-0226: Vulnerabilities Patched in Progress MOVEit Transfer (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Progress MOVEit Transfer vulnerabilities in Custom Reports and Ad Hoc modules patched
- Unauthorized data access and corruption possible via query manipulation
- XSS vulnerability in Ad Hoc module due to insufficient input sanitization
"Progress has fixed vulnerabilities in MOVEit Transfer, specifically in the Custom Reports and Ad Hoc modules, affecting versions 25.0.0–25.0.7, 25.1.0–25.1.3, and 26.0.0 prior to 26.0.1. The flaws allow unauthorized data access, data corruption, and cross-site scripting."
no comments yet.