CVE-2026-15968: Progress MOVEit Transfer
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
Affected products
- Progress MOVEit Transfer: before 2025.1.5 (fixed in 2025.1.5); from 2026.0.0, before 2026.0.3 (fixed in 2026.0.3)
Published 2026-07-23. Last modified 2026-07-30.