CVE-2019-18465: Ipswitch MOVEit Transfer

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the MySQL database is being used.

Affected products

  • Ipswitch MOVEit Transfer: from 11.1, before 11.1.3 (fixed in 11.1.3)

Published 2019-10-31. Last modified 2026-06-17.