---
schema: 1
kind: vulnerability
title: "Progress MOVEit Transfer: pre-auth SFTP DoS (CVE-2026-10699), admin table-scope bypass (CVE-2026-10698) and stored XSS (CVE-2026-11903), patched 2026.0.2"
headline: "CERT-FR flags three new MOVEit Transfer CVEs — a pre-auth SFTP memory-leak DoS is reachable on any exposed instance (no exploitation yet)"
summary: >
  France's CERT-FR/ANSSI advisory CERTFR-2026-AVI-0856 (2026-07-10) covers three newly-patched flaws in
  Progress MOVEit Transfer, the managed file-transfer product with a history of mass exploitation (Cl0p,
  2023): CVE-2026-10699 (CVSS 7.5) is an unauthenticated SFTP-service memory leak an attacker can drive to
  denial of service; CVE-2026-10698 (CVSS 7.2) lets an admin-level user bypass Custom Reports table-scope
  restrictions to read or manipulate data outside scope; CVE-2026-11903 (CVSS 8.0) is a low-privilege stored
  XSS in the Ad Hoc module. No exploitation or public PoC is reported. Fixed in 2026.0.2 (and the
  2025.0.8 / 2025.1.4 branch releases); Swiss/EU public-sector and finance operators running internet-facing
  MOVEit should prioritise the upgrade given the product's exposure profile and exploitation history.
discovered_at: "2026-07-11T13:05:00Z"
event_date: "2026-07-10"
run_id: 2026-07-11T1210Z-intel
priority: notable
immediate_action: null
tags: [vulnerabilities, dos, pre-auth, patch-available]
regions: [global, europe, switzerland]
sectors: [public-sector, finance]
entities: []
techniques: [T1190, T1499.004, T1059.007]
affected_products: ["Progress MOVEit Transfer"]
cves:
  - id: CVE-2026-10699
    cvss: "7.5"
    epss: null
    type: dos
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "2026.x < 2026.0.2; 2025.1.x < 2025.1.4; 2025.0.x < 2025.0.8"
    fixed: "2026.0.2 / 2025.1.4 / 2025.0.8"
  - id: CVE-2026-10698
    cvss: "7.2"
    epss: null
    type: logic-flaw
    vector: zero-click
    auth: admin-required
    status: [patch-available]
    affected: "2026.x < 2026.0.2; 2025.1.x < 2025.1.4; 2025.0.x < 2025.0.8"
    fixed: "2026.0.2 / 2025.1.4 / 2025.0.8"
  - id: CVE-2026-11903
    cvss: "8.0"
    epss: null
    type: xss
    vector: user-interaction
    auth: post-auth
    status: [patch-available]
    affected: "2026.x < 2026.0.2; 2025.1.x < 2025.1.4; 2025.0.x < 2025.0.8"
    fixed: "2026.0.2 / 2025.1.4 / 2025.0.8"
sources:
  - url: "https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0856/"
    publisher: "CERT-FR / ANSSI"
    date: "2026-07-10"
    role: primary
  - url: "https://cve.threatint.eu/CVE/CVE-2026-10699"
    publisher: "CVE record (Progress CNA, via THREATINT)"
    date: "2026-07-08"
    role: corroborating
  - url: "https://cve.threatint.eu/CVE/CVE-2026-10698"
    publisher: "CVE record (Progress CNA, via THREATINT)"
    date: "2026-07-08"
    role: corroborating
  - url: "https://cve.threatint.eu/CVE/CVE-2026-11903"
    publisher: "CVE record (Progress CNA, via THREATINT)"
    date: "2026-07-08"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: "Primary is the CERT-FR/ANSSI advisory CERTFR-2026-AVI-0856; per-CVE CVSS scores, CWE classes and affected-version ranges are corroborated against the Progress-assigned CVE records (verified on CVE.org, cited via the THREATINT mirror). Progress's own MOVEit community security bulletin is a JavaScript-only page that would not render via WebFetch or the reader this run, so it is not cited directly. Version note: CERT-FR states the 2026.x fixed boundary as 2026.0.2 while the CVE metadata lists 2026.0.1 for the 2026.x branch — verify against your own build number rather than either secondary figure. confidence: medium."
confidence: medium
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Inventory internet-facing MOVEit Transfer instances and upgrade to 2026.0.2 (or the 2025.1.4 / 2025.0.8 branch release), verifying the installed build number against the vendor's fixed-version list rather than the branch label."
  - "Prioritise the SFTP-reachable instances first: CVE-2026-10699 is exploitable pre-authentication to cause denial of service, so any MOVEit whose SFTP port is exposed to untrusted networks is reachable without credentials."
  - "Review Custom Reports admin-account scoping (CVE-2026-10698) and restrict Ad Hoc module use to trusted users pending patch (CVE-2026-11903)."
migrated_from: null
---

France's national CERT (CERT-FR/ANSSI) published advisory [CERTFR-2026-AVI-0856](https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0856/) on 2026-07-10 for three newly-disclosed vulnerabilities in Progress MOVEit Transfer, a managed file-transfer product whose 2023 Cl0p mass-exploitation campaign against roughly 2,600 organisations makes any internet-facing MOVEit flaw worth prompt attention. The most exposure-relevant is **CVE-2026-10699** (CVSS 3.1 7.5, [Progress CNA record](https://cve.threatint.eu/CVE/CVE-2026-10699)), a missing-release-of-memory flaw in the SFTP service: memory is not freed after its effective lifetime, letting an unauthenticated remote attacker exhaust memory and force a denial of service on any instance whose SFTP listener is reachable. **CVE-2026-10698** (CVSS 7.2, [Progress CNA record](https://cve.threatint.eu/CVE/CVE-2026-10698)) is a query-logic flaw in the Custom Reports module that lets an attacker already holding admin-level privileges bypass a report's table-scope restrictions to read or manipulate data outside its intended scope, and **CVE-2026-11903** (CVSS 8.0, [Progress CNA record](https://cve.threatint.eu/CVE/CVE-2026-11903)) is a stored cross-site-scripting flaw in the Ad Hoc module that a low-privileged authenticated user can plant to run script in another user's session. CERT-FR gives the fixed release as MOVEit Transfer 2026.0.2, with the 2025.0.8 and 2025.1.4 branch releases carrying the same fixes; no active exploitation or public proof-of-concept is reported for any of the three.

**Defender note:** the actionable driver here is exposure, not exploitation — this is a prompt patch-prioritisation item for a product with a documented mass-exploitation history, not an active-incident response. Rank internet-facing instances by whether their SFTP port is reachable (the only pre-authentication path, CVE-2026-10699), and treat MOVEit as the kind of edge MFT asset where a future exploitation wave would move fast. **Detection:** for the DoS, watch MOVEit host memory/RSS growth and SFTP session churn for abnormal unauthenticated connection patterns that precede service degradation; for the stored XSS, monitor Ad Hoc-module content for injected script and administrative-session anomalies. The benign-lookalike discriminator for the DoS is that legitimate SFTP clients complete authentication and transfer, whereas the abuse pattern is repeated pre-auth connection/allocation churn from a source that never progresses to a successful transfer.
