CVE-2023-34362Active Exploitation(progress / moveit_cloud)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch progress moveit_cloud systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-06-23. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • moveit_cloud
  • moveit_transfer

Threat summary

  • Active exploitation appears in 11 classified signals
  • Patch or workaround signal is available
  • 21 mentions across 16 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 11 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 3 signals
  • General: 7 classified signals
  • Peaked 13d ago at 3 mentions (2026-07-13); latest day: 1
  • 21 total mentions across 16 days

Affected systems

Vendors
Products
moveit_cloudmoveit_transfer

Deep dive

Activity timeline21 mentions / 16d
01223Mentions · 2026-02-17: 2Mentions · 2026-05-06: 1Mentions · 2026-07-13: 3Mentions · 2026-07-21: 1Mentions · 2026-07-23: 1Mentions · 2026-08-04: 1Mentions · 2026-08-17: 1Mentions · 2026-08-20: 2Mentions · 2026-08-23: 1Mentions · 2026-08-25: 1Mentions · 2026-09-13: 1Mentions · 2026-09-14: 1Mentions · 2026-09-18: 2Mentions · 2026-09-19: 1Mentions · 2026-09-21: 1Mentions · 2026-10-07: 1Active Exploitation · 2026-02-17: 1Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-07-13: 2Active Exploitation · 2026-07-21: 1Active Exploitation · 2026-08-04: 1Active Exploitation · 2026-08-20: 2Active Exploitation · 2026-08-25: 1Active Exploitation · 2026-09-19: 1Active Exploitation · 2026-09-21: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-07-13: 2Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-08-23: 1Patch / Workaround · 2026-09-19: 1Technical Details · 2026-02-17: 1Technical Details · 2026-08-04: 1Technical Details · 2026-08-23: 102-1705-0607-1307-2107-2308-0408-1708-2008-2308-2509-1309-1409-1809-1909-2110-07
Signal classification4 categories
Active Exploitation
1050.0%
General
735.0%
Patch
210.0%
Disclosure
15.0%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-02-172
Active Exploitation1General1
2026-05-061
Patch1
2026-07-133
Active Exploitation2Patch1
2026-07-211
Active Exploitation1
2026-07-231
General1
2026-08-041
Active Exploitation1
2026-08-171
General1
2026-08-202
Active Exploitation2
2026-08-231
Disclosure1
2026-08-251
Active Exploitation1
2026-09-131
General1
2026-09-141
General1
2026-09-182
General2
2026-09-191
Active Exploitation1
2026-09-211
Active Exploitation1
Full discourse20 posts
  • Nitin Gavhane@NitinGavhane_
    General

    CVE Vulnerabilities That Shaped the Bug Bounty World A quick timeline worth knowing: 1. CVE-2014-0160 • Heartbleed - 2014 2. CVE-2014-6271 • Shellshock - 2014 3. CVE-2016-5195 • Dirty COW - 2016 4. CVE-2017-0144 • EternalBlue - 2017 5. CVE-2017-5638 • Apache Struts RCE - 2017 6. CVE-2018-7600 • Drupalgeddon2 - 2018 7. CVE-2019-0708 • BlueKeep - 2019 8. CVE-2021-44228 • Log4Shell - 2021 9. CVE-2023-34362 • MOVEit - 2023 10. CVE-2024-3094 • XZ Utils - 2024 Learn the CVE → understand the root cause → study the patch → reproduce safely in a lab. #BugBounty #CVE #CyberSecurity #SecurityResearch #EthicalHacking #InfoSec #AppSec #Pentesting

    Post summary

    The post is a concise timeline of historically significant CVEs that shaped the bug bounty community, urging readers to understand root causes and study patches for safe lab reproduction, without providing PoCs, exploits, or detailed technical information.

    31411016411.3K
    3.5K followersView on X
  • cyber_security_puns@PunsCyber
    General

    Cows also created the 2023 MOO-VEit vulnerability CVE-2023-34362.

    Post summary

    The statement only notes that 'Cows' created CVE-2023-34362, a 2023 MOO-VEit vulnerability, with no supporting technical or operational detail.

    11030274
    685 followersView on X
  • Bhavesh Verma@xbhaveshverma

    CVEs Explainer #5 CVE-2023-34362 (MOVEit Transfer SQL Injection) This zero-day SQL injection in Progress MOVEit Transfer, a managed file transfer solution, sparked a massive data breach campaign in 2023. Unauthenticated attackers could access the database and exfiltrate sensitive data. The Cl0p ransomware gang exploited it to breach thousands of organizations worldwide, making it one of the most impactful vulnerabilities of the year.

    00111118
    104 followersView on X
  • ro0TCr4k@ro0TCr4k
    Active Exploitation

    Attackers are inside your network. MOVEit CVE-2023-34362 isn't a future threat—it's a current zero-day being leveraged right now. We've already deployed mitigations for clients. Patch advisory isn't a suggestion; it's your weekend plan.

    Post summary

    The post alerts that attackers are actively exploiting CVE‑2023‑34362 and that mitigations/patches have already been deployed for clients.

    01020218
    481 followersView on X
  • ro0TCr4k@ro0TCr4k
    Active Exploitation

    MOVEit zero-day (CVE-2023-34362) exploitation is accelerating. Cl0p is weaponizing it for mass data theft. We're deep in the trenches analyzing their shifting tactics and infrastructure. Defense requires adaptive, real-time response.

    Post summary

    The text reports that CVE‑2023‑34362 is being actively exploited by the Cl0p ransomware group, accelerating data theft operations.

    01010139
    260 followersView on X
  • ro0TCr4k@ro0TCr4k
    Patch

    MOVEit zero-days keep evolving. CVE-2023-34362 was just the opening act. Our threat hunters are tracking new TTPs from Cl0p in real-time. Patching is mandatory, but proactive hunting is non-negotiable now.

    Post summary

    The post emphasizes mandatory patching for CVE-2023-34362 in MOVEit, coupled with proactive threat hunting due to evolving TTPs from Cl0p.

    01010113
    260 followersView on X
  • SalvageData Recovery Services@SALVAGEDATA
    Active Exploitation

    Clop: 1,254+ victims. MOVEit alone: 2,000+ orgs, 62M exposed. CVE-2023-34362. Encryption: optional. Full attack chain, IOCs, and IR checklist: https://www.provendata.com/blog/clop-ransomware #CyberSecurity #Ransomware #DFIR #ThreatIntel #IncidentResponse

    Post summary

    The post documents a large-scale, active use of CVE‑2023‑34362 by Clop ransomware, with over 2,000 organizations affected and 62 million data points exposed.

    0001072
    405 followersView on X
  • CVEDatabase.com@cvedatabase
    Active Exploitation

    🚨 Would this get past your patching process? CVE-2023-34362 (MOVEit Transfer) A single SQL injection flaw The scary part wasn’t the exploit. It was how many fully patched orgs still got hit. 📘 Full CVE details & attack chain: https://cvedatabase.com/cve/CVE-2023-34362 #MOVEit #DataBreach #CVE

    Post summary

    The post highlights that many fully patched organizations were still impacted by CVE‑2023‑34362, a SQL injection flaw in MOVEit Transfer, underscoring real‑world exploitation.

    1000091
    2 followersView on X
  • ro0TCr4k@ro0TCr4k
    Active Exploitation

    The MOVEit zero-day CVE-2023-34362 is being actively exploited by Cl0p ransomware group. Patching is critical, but the real focus should be on monitoring for lateral movement from compromised file transfer appliances. The threat is real and now.

    Post summary

    The text reports that CVE-2023-34362 is being actively exploited by the Cl0p ransomware group, emphasizing the need for patching and monitoring for lateral movement.

    00000132
    509 followersView on X
  • ro0TCr4k@ro0TCr4k
    Active Exploitation

    Patch your MOVEit instances NOW. CVE-2023-34362 is being exploited actively in the wild, and the blast radius is massive. Defense starts with visibility and rapid response. #MOVEit

    Post summary

    The text explicitly reports active in-the-wild exploitation of CVE-2023-34362 in MOVEit and urges immediate patching. Active exploitation is the core message, overriding the patch call.

    0000078
    511 followersView on X
  • ro0TCr4k@ro0TCr4k
    General

    MOVEit CVE-2023-34362 still dominating incident response calls. This isn't a sprint, it's a marathon. Third-party dependencies remain the attack surface no one budgets for.

    Post summary

    The tweet mentions CVE-2023-34362 in the context of ongoing incident response activity and third-party dependency risks, but lacks any specific indicators such as PoC, exploit tools, technical details, patches, or active exploitation claims.

    0000077
    508 followersView on X
  • ro0TCr4k@ro0TCr4k
    General

    The MOVEit vulnerability fallout continues. We're tracking the expanding blast radius of CVE-2023-34362. The supply chain implications are devastating. RootCrak is actively analyzing the second-order effects.

    Post summary

    The text highlights the ongoing fallout and supply chain impact of CVE-2023-34362, noting RootCrak's analysis of secondary effects, but lacks specifics on exploitation methods, patches, or direct evidence of active use.

    0000066
    508 followersView on X
  • chaos@konig0000
    General

    CVE Vulnerabilities That Shaped the Bug Bounty World A quick timeline worth knowing: 1. CVE-2014-0160 • Heartbleed - 2014 2. CVE-2014-6271 • Shellshock - 2014 3. CVE-2016-5195 • Dirty COW - 2016 4. CVE-2017-0144 • EternalBlue - 2017 5. CVE-2017-5638 • Apache Struts RCE - 2017 6. CVE-2018-7600 • Drupalgeddon2 - 2018 7. CVE-2019-0708 • BlueKeep - 2019 8. CVE-2021-44228 • Log4Shell - 2021 9. CVE-2023-34362 • MOVEit - 2023 10. CVE-2024-3094 • XZ Utils - 2024 Learn the CVE → understand the root cause → study the patch → reproduce safely in a lab.

    Post summary

    No specific CVE report was provided for analysis. The text is a general CVE timeline and learning prompt, without PoC links, exploit tools, active exploitation, patches, or detailed vulnerability information.

    00000121
    19.8K followersView on X
  • ro0TCr4k@ro0TCr4k
    Active Exploitation

    The MOVEit CVE-2023-34362 fallout continues. New victims surface weekly, proving this wasn't a single patch-and-forget event. Attackers are still probing for unpatched instances. We're tracking the exploitation patterns closely.

    Post summary

    The CVE-2023-34362 in MOVEit remains actively exploited, with attackers targeting unpatched servers and new victim incidents occurring weekly.

    0000062
    472 followersView on X
  • RST Cloud@rst_cloud
    Disclosure

    #threatreport #HighCompleteness VEEAM UNDER FIRE: Understanding CVE-2026–44963 & Ransomware Group Exploit Claims | 20-08-2026 Source: https://theravenfile.com/2026/08/20/veeam-under-fire-understanding-cve-2026-44963-ransomware-group-exploit-claims/ Key details below ↓ 🧑‍💻Actors/Campaigns: Lynx_ransomware Carbanak Dragonforce Vice_society Lazarus Bluenoroff Warlock Hunters_international Teampcp 💀Threats: Lynx, Akira_ransomware, Fog_ransomware, Credential_harvesting_technique, Credential_dumping_technique, Qilin_ransomware, Rclone_tool, Conti, Blackbasta, Kerberoasting_technique, Bitsadmin_tool, Pdq_deploy_tool, Cuba_ransomware, Cobalt_strike_tool, Bughatch, Burntcigar, Metasploit_tool, Defendercontrol_tool, Veeamhax, Anydesk_tool, Simplehelp_tool, Medusa_ransomware, Clop, Lemurloot, Rhysida, Secretsdump_tool, Putty_tool, Nltest_tool, Ransomhub, Lockbit, Dcsync_technique, Gentlekiller, Av-killer, Hexkiller, Throttleblood, Havockiller, Oxideharvest, Impacket_tool, Wmiexec_tool, Netexec_tool, Inc_ransomware, Anubis, Dire_wolf, Wevtutil_tool, Shadow_copies_delete_technique, Vssadmin_tool, Everest_ransomware, Supply_chain_technique, 🎯Victims: Data backup and recovery sector 🏭Industry: Critical_infrastructure 🌐Geo: Dprk, Latin american 🔓CVEs: CVE-2023-3519 \[[Vulners](https://vulners.com/cve/CVE-2023-3519)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - citrix netscaler_application_delivery_controller (<12.1-55.297, <13.0-91.13, <13.1-37.159, <13.1-49.13) - citrix netscaler_gateway (<13.0-91.13, <13.1-49.13) CVE-2026-44963 \[[Vulners](https://vulners.com/cve/CVE-2026-44963)] - CVSS V3.1: *9.4*, - Vulners: Exploitation: True CVE-2026-12569 \[[Vulners](https://vulners.com/cve/CVE-2026-12569)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ptc flexplm (le11.0m030, 11.1m020, 11.2.1.0, 12.0.0.0, 12.0.2.0) CVE-2023-34362 \[[Vulners](https://vulners.com/cve/CVE-2023-34362)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - progress moveit_cloud (<14.0.5.45, <14.1.6.97, <15.0.2.39) - progress moveit_transfer (<2021.0.7, <2021.1.5, <2022.0.5, <2022.1.6, <2023.0.2) CVE-2023-27532 \[[Vulners](https://vulners.com/cve/CVE-2023-27532)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - veeam veeam_backup_\&_replication (<11.0.1.1261, 12.0.0.1420) CVE-2024-40711 \[[Vulners](https://vulners.com/cve/CVE-2024-40711)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - veeam veeam_backup_\&_replication (<12.2.0.334) CVE-2023-0669 \[[Vulners](https://vulners.com/cve/CVE-2023-0669)] - CVSS V3.1: *7.2*, - Vulners: Exploitation: True Soft: - fortra goanywhere_managed_file_transfer (<7.1.2) CVE-2025-33073 \[[Vulners](https://vulners.com/cve/CVE-2025-33073)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - microsoft windows_10_1507 (<10.0.10240.21034) - microsoft windows_10_1607 (<10.0.14393.8148) - microsoft windows_10_1809 (<10.0.17763.7434) - microsoft windows_10_21h2 (<10.0.19044.5965) ... 📚TTPs: ⚔️Tactics: 3 🛠️Technics: 0 🤖LLM extracted TTPs:` T1068, T1078, T1210 🧨IOCs: - File: 14 - Hash: 1 💽Software: MSSQL, PostgreSQL, Hyper-V, curl, PDQ Deploy, Windows Defender, FortiGate, PsExec, MOVEit, GoAnywhere, ... 🔢Algorithms: chacha20, md5 ⚙️Win Services: SQLAgent$VEEAMSQL2008R2, VeeamTransportSvc, BackupExecJobEngine, SQLSERVERAGENT, Symantec System Recovery 📜Programming Languages: powershell #threatreport: CVE-2026-44963 is described as a critical remote code execution vulnerability affecting Veeam Backup & Replication 12.x. The flaw reportedly involves insecure deserialization and allows a low-privileged, authenticated domain user to execute arbitrary code over the network against a domain-joined Veeam backup server. Successful exploitation can result in SYSTEM-level control of the server, making the vulnerability particularly significant because backup infrastructure often provides access to sensitive data and recovery operations. The report gives the vulnerability a CVSS score of 9.4 and compares it with earlier Veeam deserialization vulnerabilities, including CVE-2024-40711. The Lynx ransomware group allegedly claimed to use a private or improved version of the vulnerability that does not require domain credentials. An underground forum advertisement similarly claimed to offer an exploit that bypasses the June 2026 patch and achieves unauthenticated SYSTEM-level remote code execution. As of mid-August 2026, these claims had not been independently verified. The report notes that there was no public technical analysis, confirmed exploitation evidence, or vendor acknowledgment demonstrating a genuine unauthenticated bypass or residual vulnerability. The claims may therefore represent negotiation tactics intended to increase ransom demands or protect an alleged exploit. The report also connects the vulnerability to a private exploit advertised in 2025, assessing that it may have been an early version of, or the same underlying issue as, CVE-2026-44963. Veeam has historically been targeted by ransomware groups, including Akira, Fog, Cuba, and FIN7, because compromising backup servers enables attackers to disrupt recovery operations before deploying ransomware. Another major Veeam attack vector is CVE-2023-27532, which can expose credentials from the Veeam backup service and database. Attackers may use these credentials for initial access or lateral movement, including through post-compromise credential-dumping activity. Regardless of whether the alleged unauthenticated exploit exists, the authenticated RCE described for CVE-2026-44963 presents a serious risk wherever domain accounts or backup infrastructure are compromised.

    Post summary

    The report discloses the details of CVE-2026-44963, a critical RCE in Veeam Backup, notes unverified claims of unauthenticated exploitation by ransomware groups, and references the June 2026 patch while indicating no confirmed active exploitation.

    00000241
    779 followersView on X
  • ro0TCr4k@ro0TCr4k
    Active Exploitation

    The MOVEit zero-day (CVE-2023-34362) exploitation is accelerating. Cl0p is weaponizing it at scale. If you're running the software, patching is no longer optional—it's an emergency. We're seeing novel post-exploitation techniques emerge.

    Post summary

    The text asserts that CVE-2023-34362 in MOVEit is being actively exploited by Cl0p, with accelerating attacks and new post‑exploitation techniques; urgent patching is urged.

    00000129
    472 followersView on X
  • ro0TCr4k@ro0TCr4k
    Active Exploitation

    The MOVEit CVE-2023-34362 situation is evolving fast. It's not just about patching anymore—it's about spotting the stealthier post-exploitation activity we're seeing in the wild. Stay vigilant.

    Post summary

    The statement indicates that CVE‑2023‑34362 is actively exploited in the wild, with attackers demonstrating stealthier post‑exploitation behavior that requires vigilance.

    0000078
    472 followersView on X
  • Jordan Saunders@jsaunders_
    Active Exploitation

    Media credits: 1. MOVEit SQLi Zero-Day (CVE-2023-34362) Exploited by CL0P Ransomware Group https://www.akamai.com/blog/security-research/moveit-sqli-zero-day-exploit-clop-ransomware 2. MOVEit Vulnerability CVE-2023-34362 Breach Deep Dive https://www.youtube.com/watch?v=Ju45T6xDICQ

    Post summary

    The media credits highlight that CVE-2023-34362, an SQLi zero‑day in MOVEit, has been actively exploited by the CL0P ransomware group, though no PoC or patch is mentioned in the provided text.

    00000179
    13.0K followersView on X
  • Proven Data@Proven_Data
    General

    Clop: 1,254+ victims. MOVEit alone: 2,000+ orgs, 62M exposed. CVE-2023-34362. Encryption: optional. Full attack chain, IOCs, and IR checklist: https://www.provendata.com/blog/clop-ransomware #CyberSecurity #Ransomware #DFIR #ThreatIntel #IncidentResponse

    Post summary

    The post reports that Clop ransomware has affected over 1,200 victims and exposed more than 62 million users via MOVEit, referencing CVE-2023-34362. It provides an attack chain and incident‑response resources but offers no technical or patch details.

    0000087
    907 followersView on X
  • Paul Fregonese@paul_fregonese
    Patch

    MOVEit (CVE-2023-34362) had a patch. Most orgs hit by Cl0p hadn't applied it in the 2-week window between disclosure and mass exploitation. Patch velocity vs. attacker velocity. You're losing that race. https://t.co/F7pYgaeSNP

    Post summary

    The tweet highlights that MOVEit CVE‑2023‑34362 already had a patch, yet many organizations failed to apply it before Cl0p’s mass exploitation, emphasizing the need for rapid patch deployment.

    0000050
    44 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appprogressmoveit_cloud---
Appprogressmoveit_transfer---

Explore more