External risk intelligence

Progress MOVEit Transfer Improper Authentication Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-10697

Progress MOVEit Transfer is a managed file transfer solution designed specifically to facilitate the transfer of data between organizations and external partners over the internet. It is typically deployed as a public-facing web application intended to be accessed by external users.

Authentication Bypass

Progress Moveit Transfer

before 2025.1.52026.0.0 to before 2026.0.3

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Progress MOVEit Transfer, a managed file transfer solution. The Improper Authentication issue could allow unauthorized access and manipulation of data. The primary concern at this time is confirming if your organization uses this technology and assessing potential exposure.

  • Authentication flaw impacts MOVEit Transfer.
  • Critical flaw enables unauthorized access.
  • Confirm use; assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit an improper authentication flaw in Progress MOVEit Transfer to gain unauthorized access. This vulnerability allows for unauthenticated access to the system, potentially leading to severe impacts on data confidentiality, integrity, and availability.

  • No authentication required to access.
  • Vulnerable authentication mechanism is triggered.
  • High risk to data confidentiality, integrity, availability.

Live Threat

Current exploitation, exposure, and threat context

An improper authentication vulnerability in Progress MOVEit Transfer could allow an unauthenticated attacker to gain unauthorized access to sensitive information, modify data, or disrupt service operations when the system is accessible via a network.

  • System and user data.
  • Via network access.
  • Data compromise and service disruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Progress MOVEit Transfer improper authentication vulnerability likely impacts teams responsible for managing external file transfer solutions, such as application owners, platform teams, and potentially network/security teams overseeing internet-facing applications. The first practical step is to identify all MOVEit Transfer instances, confirm their exposure and business criticality, and then determine the accountable owner for remediation planning.

  • Identify MOVEit Transfer instances and ownership.
  • Verify external reachability and business impact.
  • Plan and coordinate remediation efforts.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Progress MOVEit Transfer?

Progress MOVEit Transfer is a managed file transfer solution that organizations use to securely share sensitive data between internal teams and external partners. Because it is designed to facilitate these exchanges over the internet, it typically operates as a web application that bridges an organization's private network with external users.

What does improper authentication mean for CVE-2026-10697?

This vulnerability, classified as CWE-287, means there is a flaw in how the software verifies a user's identity. In the context of CVE-2026-10697, the system fails to correctly validate credentials, which allows an attacker to bypass the login process entirely and gain unauthorized access to the application as if they were a legitimate user.

How does an attacker trigger this vulnerability?

An attacker exploits this bug by interacting with the MOVEit Transfer web interface over a network. The vulnerability does not require the attacker to have prior user accounts or valid credentials to succeed. Simply navigating to and interacting with the affected service is sufficient to trigger the flaw; it is not dependent on specific user actions or pre-existing sessions.

Why is this CVE important for my organization?

Halo Surface Signal indicates that MOVEit Transfer is often deployed as a public-facing web application specifically to enable internet-based file sharing. This makes it highly accessible to external network traffic. If your organization hosts an affected instance, it is likely reachable by anyone on the internet, increasing the urgency to understand your specific deployment status.

What should I do if I run MOVEit Transfer?

Your first step is to create an accurate inventory of all MOVEit Transfer instances within your environment. Once identified, confirm the specific version running on each server to see if it falls within the affected ranges. After confirming, coordinate with the appropriate application owners to plan for updates, as the vulnerability requires upgrading to a secure version to resolve the underlying authentication flaw.

References