Our takeCCCS relays Progress advisory AV26-746 on vulnerabilities in MOVEit Transfer versions prior to 2025.1.5 and 2026.0.3. If you run it, update now.Cyber Resilience desk
What this means for you — Security leader:If you run MOVEit Transfer, confirm whether any instance is below 2025.1.5 or 2026.0.3 and apply the Progress updates; prioritize internet-facing systems.
What this means for you — Lean IT orgs:If you use MOVEit Transfer for file sharing, update to 2025.1.5 or 2026.0.3 now. Shops that do not run MOVEit can ignore this.
What this means for you — MSP:Inventory client estates for MOVEit Transfer; patch any version prior to 2025.1.5 or 2026.0.3, with internet-facing instances first.
What this means for you — Researcher:Progress fixed issues in MOVEit Transfer prior to 2025.1.5 and 2026.0.3; CCCS relayed the advisories as AV26-746. Review the vendor write-ups for CVE and exploitability detail.