2026-07-11NOTABLECERT-FR flags three new MOVEit Transfer CVEs; a pre-auth SFTP memory-leak DoS is reachable on any exposed instance (no exploitation yet)
Progress MOVEit Transfer Ad Hoc module stored XSS, low-priv authenticated (CVSS 8.0; CERT-FR AVI-0856)
cve · CVE-2026-11903
Coverage
1
first 2026-07-11 → last 2026-07-11
Latest activity
2026-07-11
CERT-FR flags three new MOVEit Transfer CVEs; a pre-auth SFTP memory-leak DoS is reachable on any exposed…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, finance · regions: europe, switzerland
Sources cited
4
2 hosts
Action items (3)
Do-now tasks recorded on the entries about CVE-2026-11903, newest first. Check the date before acting on an older one.
- Inventory internet-facing MOVEit Transfer instances and upgrade to 2026.0.2 (or the 2025.1.4 / 2025.0.8 branch release), verifying the installed build number against the vendor's fixed-version list rather than the branch label.2026-07-11CVE-2026-10699 +2
- Prioritise the SFTP-reachable instances first: CVE-2026-10699 is exploitable pre-authentication to cause denial of service, so any MOVEit whose SFTP port is exposed to untrusted networks is reachable without credentials.2026-07-11CVE-2026-10699 +2
- Review Custom Reports admin-account scoping (CVE-2026-10698) and restrict Ad Hoc module use to trusted users pending patch (CVE-2026-11903).2026-07-11CVE-2026-10699 +2
Defender insights
What each entry about CVE-2026-11903 tells a defender to do, newest first.
Detection
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (3 across 3 tactics)
3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter: JavaScript
- ImpactEndpoint Denial of Service: Application or System Exploitation
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903 · ATT&CK page ↗
Execution TA0002
T1059.007Command and Scripting Interpreter: JavaScript×1
Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.
Evidence: 2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903 · ATT&CK page ↗
Impact TA0040
T1499.004Endpoint Denial of Service: Application or System Exploitation×1
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users. Some systems may automatically restart critical applications and services when crashes occur, but they can likely be re-exploited to cause a persistent denial of service (DoS) condition.
Evidence: 2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903 · ATT&CK page ↗
Entries about Progress MOVEit Transfer Ad Hoc module stored XSS, low-priv authenticated (CVSS 8.0; CERT-FR AVI-0856) (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Cl0p×1
- Progress MOVEit Transfer×1
- Progress MOVEit Transfer Custom Reports table-scope bypass, admin-privileged (CVSS 7.2; CERT-FR AVI-0856)×1
- Progress MOVEit Transfer SFTP-service memory-leak pre-auth denial of service (CVSS 7.5; CERT-FR AVI-0856)×1
Where this entity is cited
Source distribution
- cve.threatint.eu3 (75%)
- cert.ssi.gouv.fr1 (25%)
External references
All cited sources (4)
- cert.ssi.gouv.frprimaryCERT-FR / ANSSIhttps://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0856/
- cve.threatint.euCVE record (Progress CNA, via THREATINT)https://cve.threatint.eu/CVE/CVE-2026-10698
- cve.threatint.euCVE record (Progress CNA, via THREATINT)https://cve.threatint.eu/CVE/CVE-2026-10699
- cve.threatint.euCVE record (Progress CNA, via THREATINT)https://cve.threatint.eu/CVE/CVE-2026-11903