SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-8651

LOW · CVSS 3.7 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A limited authentication bypass vulnerability exists in the HTTPS module of Progress MOVEit Transfer, allowing attackers to spoof authentication under specific conditions. Although the severity is rated low, organizations using affected versions prior to 2025.0.7 and between 2025.1.0 and 2025.1.3 should prioritize patching to mitigate potential unauthorized access risks. Users of MOVEit Transfer should assess their deployments and apply updates accordingly to enhance security.

CVE
CVE-2026-8651
Severity
LOW
CVSS
3.7
EPSS
0.21%

Original NVD Description

Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)