CVE-2026-11903Patch(progress / moveit_transfer)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch progress moveit_transfer systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • moveit_transfer

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 2 mentions (2026-07-09); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
moveit_transfer

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-09: 2Mentions · 2026-07-10: 1Patch / Workaround · 2026-07-09: 2Technical Details · 2026-07-09: 207-0907-10
Signal classification1 categories
Patch
3100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-092
Patch2
2026-07-101
Patch1
Full discourse3 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Progress patched three MOVEit Transfer flaws, including a stored XSS bug (CVE-2026-11903). No exploitation is confirmed. Update now. #MOVEit #MOVEitTransfer #StoredXSS #XSS #CVE #ProgressSoftware #PatchNow #InfoSec http://securityonline.info/moveit-transfer-stored-xss/

    Post summary

    The text announces that Progress has patched a stored XSS vulnerability (CVE-2026-11903) in MOVEit Transfer, with no known exploitation and no PoC or active attack reports.

    03070783
    12.9K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    MOVEit Transfer Critical Security Bulletin – June 2026  – (CVE-2026-10699, CVE-2026-10698, CVE-2026-11903) - Progress Community https://community.progress.com/s/article/MOVEit-Transfer-Critical-Security-Bulletin-June-2026

    Post summary

    The text announces a critical security bulletin for three CVEs, implying that a patch or mitigation likely exists, but no specific details are provided.

    00021590
    6.9K followersView on X
  • ThreatWire@ThreatWire_
    Patch

    🚨 CVE-2026-11903: Progress has patched three MOVEit Transfer vulnerabilities, including a stored XSS flaw. No active exploitation has been confirmed. Update now. #CyberSecurity #CVE #MOVEit #XSS #ThreatWire

    Post summary

    The post announces that Progress has patched three MOVEit Transfer vulnerabilities, including a stored XSS flaw, and notes that no active exploitation has been seen so an update is recommended.

    0001063
    66 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appprogressmoveit_transfer---
Appprogressmoveit_transfer2026.0.0--

Explore more