Incident · 8-K Item 8.01
Progress Software discloses the MOVEit Transfer zero-day vulnerability
Compiled 2026-09-27 from public records. By the cisonews.net Desk.
Progress Software disclosed on June 5, 2023 that it had discovered a zero-day vulnerability in MOVEit Transfer, its managed file transfer product, after a customer reported unusual activity on the evening of May 28. The vulnerability could allow escalated privileges and access to a customer's underlying environment.
Timeline in the filing
On May 30 Progress contacted all MOVEit Transfer and MOVEit Cloud customers and took the cloud service down. A patch followed.
Business context
Progress sized the product line against its revenue. It said it had stayed fully operational, had found no unauthorized activity beyond the two MOVEit products, and did not expect a material effect.
Scope of this entry
This entry covers the vendor's disclosure. The filing does not list affected customers, and incidents that customers disclosed themselves would have their own entries.
Sources
- 2023-06-05 · AProgress Software Corporation, Form 8-K (SEC EDGAR), published June 5, 2023
Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.
See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.