Skip to content
cisonews.net

Incident · 8-K Item 8.01

Progress Software discloses the MOVEit Transfer zero-day vulnerability

Compiled 2026-09-27 from public records. By the cisonews.net Desk.

Progress Software disclosed on June 5, 2023 that it had discovered a zero-day vulnerability in MOVEit Transfer, its managed file transfer product, after a customer reported unusual activity on the evening of May 28. The vulnerability could allow escalated privileges and access to a customer's underlying environment.

Timeline in the filing

On May 30 Progress contacted all MOVEit Transfer and MOVEit Cloud customers and took the cloud service down. A patch followed.

Business context

Progress sized the product line against its revenue. It said it had stayed fully operational, had found no unauthorized activity beyond the two MOVEit products, and did not expect a material effect.

Scope of this entry

This entry covers the vendor's disclosure. The filing does not list affected customers, and incidents that customers disclosed themselves would have their own entries.

Sources

  1. 2023-06-05 · AProgress Software Corporation, Form 8-K (SEC EDGAR), published June 5, 2023

Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.

See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.