SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15966

HIGH · CVSS 7.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

A vulnerability in Progress MOVEit Transfer allows for a permissive cross-domain security policy, potentially exposing sensitive data to untrusted domains. This high-severity issue could lead to unauthorized access and data leakage, making it critical for organizations using affected versions prior to 2025.1.5 and between 2026.0.0 and 2026.0.3 to prioritize remediation efforts.

CVE
CVE-2026-15966
Severity
HIGH
CVSS
7.5
EPSS
0.20%

Original NVD Description

Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)