Moveit transfer
This hub aggregates every CVE we track for Moveit transfer, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
41
CVEs tracked
10
Critical
20
High
1
In CISA KEV
Severity distribution
HIGH20CRITICAL10MEDIUM7LOW4
Monthly trend
0
0
0
0
0
0
1
0
0
0
0
0
0
1
1
0
1
0
0
0
0
0
12
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Moveit transfer.
- CVE-2026-15968Stored XSS vulnerability in MOVEit Transfer7.1
- CVE-2026-15967MOVEit Transfer refresh-token processing does not enforce updated account restrictions7.5
- CVE-2026-15966Improper CORS handling in MOVEit Transfer7.5
- CVE-2026-10697MFA Bypass in MOVEit Transfer7.5
- CVE-2026-8801File Extension Restriction Bypass in MOVEit Transfer3.5
- CVE-2026-8800Cross-Org External Token Metadata accessible to AuditUser role2.7
- CVE-2026-8651IPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit Transfer3.7
- CVE-2026-8650Authenticated Path Traversal allows MOVEit admins to view arbitrary system files4.5
- CVE-2026-8649Institution scope bypass vulnerability in custom reports6.4
- CVE-2026-11903Stored XSS in MOVEit Transfer Ad Hoc module8.0
- CVE-2026-10699Memory leak in SFTP service can result in a denial of service in MOVEit Transfer7.5
- CVE-2026-10698Table scope bypass vulnerability in custom reports7.2
- CVE-2025-11235MOVEit Transfer REST API does not require current password in order to initiate the password change process3.7
- CVE-2025-13147External Service Interaction (DNS)5.3
- CVE-2025-10932AS2 module allows uncontrolled file uploads8.2
Product normalization is registry-driven with AI assist and human review. How it works