CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to Daily brief 2026-07-11
NOTABLECVE-2026-10699 +2NATOA2vulnerability

Progress MOVEit Transfer: pre-auth SFTP DoS (CVE-2026-10699), admin table-scope bypass (CVE-2026-10698) and stored XSS (CVE-2026-11903), patched 2026.0.2

CERT-FR flags three new MOVEit Transfer CVEs; a pre-auth SFTP memory-leak DoS is reachable on any exposed instance (no exploitation yet)

Defender actions

  • Inventory internet-facing MOVEit Transfer instances and upgrade to 2026.0.2 (or the 2025.1.4 / 2025.0.8 branch release), verifying the installed build number against the vendor's fixed-version list rather than the branch label.
  • Prioritise the SFTP-reachable instances first: CVE-2026-10699 is exploitable pre-authentication to cause denial of service, so any MOVEit whose SFTP port is exposed to untrusted networks is reachable without credentials.
  • Review Custom Reports admin-account scoping (CVE-2026-10698) and restrict Ad Hoc module use to trusted users pending patch (CVE-2026-11903).

Analysis

France's national CERT (CERT-FR/ANSSI) published advisory CERTFR-2026-AVI-0856 on 2026-07-10 for three newly-disclosed vulnerabilities in Progress MOVEit Transfer, a managed file-transfer product whose 2023 Cl0p mass-exploitation campaign against roughly 2,600 organisations makes any internet-facing MOVEit flaw worth prompt attention. The most exposure-relevant is CVE-2026-10699 (CVSS 3.1 7.5, Progress CNA record), a missing-release-of-memory flaw in the SFTP service: memory is not freed after its effective lifetime, letting an unauthenticated remote attacker exhaust memory and force a denial of service on any instance whose SFTP listener is reachable. CVE-2026-10698 (CVSS 7.2, Progress CNA record) is a query-logic flaw in the Custom Reports module that lets an attacker already holding admin-level privileges bypass a report's table-scope restrictions to read or manipulate data outside its intended scope, and CVE-2026-11903 (CVSS 8.0, Progress CNA record) is a stored cross-site-scripting flaw in the Ad Hoc module that a low-privileged authenticated user can plant to run script in another user's session. CERT-FR gives the fixed release as MOVEit Transfer 2026.0.2, with the 2025.0.8 and 2025.1.4 branch releases carrying the same fixes; no active exploitation or public proof-of-concept is reported for any of the three.

Sources4

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.