CVE-2023-36933: Progress MOVEit Transfer
High severity, CVSS 7.5. EPSS: 72.2% chance of exploitation in the next 30 days.
In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception. Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly.
Affected products
- Progress MOVEit Transfer: before 2020.1.11 (fixed in 2020.1.11); from 2021.0, before 2021.0.9 (fixed in 2021.0.9); from 2021.1.0, before 2021.1.7 (fixed in 2021.1.7); from 2022.0.0, before 2022.0.7 (fixed in 2022.0.7); from 2022.1.0, before 2022.1.8 (fixed in 2022.1.8); from 2023.0.0, before 2023.0.4 (fixed in 2023.0.4)
Published 2023-07-05. Last modified 2026-06-17.