HIGH 7.5

CVE-2026-10699: MOVEit Transfer Memory Leak Denial of Service

Progress MOVEit Transfer's Custom Reports modules contain a memory leak vulnerability that can be exploited to exhaust system resources and cause the application to become unavailable. An attacker on the network can trigger this condition without authentication, leading to a denial of service. The issue affects specific versions released in 2025 and early 2026.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
CWE-401
Affected products
2 configuration(s)
Published / Modified
2026-07-08 / 2026-07-10

NVD description (verbatim)

Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-10699 is a CWE-401 (Missing Release of Memory After Effective Lifetime) vulnerability in the Custom Reports functionality of Progress MOVEit Transfer. The affected versions are 2025.0.0 through 2025.0.7, 2025.1.0 through 2025.1.3, and 2026.0.0 before 2026.0.1. The vulnerability allows unauthenticated network-based exploitation, with no user interaction required. The CVSS 3.1 score of 7.5 reflects high availability impact; the attack vector is network-accessible and the complexity is low.

Business impact

MOVEit Transfer is commonly used for secure file transfer and data exchange in enterprise environments. A memory leak that leads to denial of service could disrupt critical file transfer workflows, impact business continuity, and prevent legitimate users from accessing the service. Organizations dependent on MOVEit for regulated data movement may face compliance and operational consequences during an outage.

Affected systems

Progress MOVEit Transfer versions 2025.0.0–2025.0.7, 2025.1.0–2025.1.3, and 2026.0.0 (before 2026.0.1) are vulnerable. Installations running the Custom Reports module are specifically at risk. Organizations should verify which versions are in production and cross-reference against the vulnerability advisory to confirm exact patch requirements.

Exploitability

The vulnerability is easily exploitable from the network without requiring authentication or user interaction. An attacker can remotely trigger the memory leak by interacting with the Custom Reports functionality. The low complexity and lack of prerequisites make this a practical attack vector for any adversary with network access to the MOVEit instance.

Remediation

Upgrade affected MOVEit Transfer instances to patched versions: 2025.0.8 or later for the 2025.0.x line, 2025.1.4 or later for the 2025.1.x line, and 2026.0.1 or later for the 2026.0.x line. Organizations should consult Progress's official advisory to confirm exact version availability and any procedural steps required during the upgrade. Verify patch application in a test environment before production deployment.

Patch guidance

Progress has released fixes for all affected branches. Organizations running 2025.0.x should upgrade to version 2025.0.8 or higher; those on 2025.1.x should move to 2025.1.4 or higher; and 2026.0.x deployments require 2026.0.1 or higher. Review the Progress MOVEit Transfer security advisory for any prerequisites, rollback procedures, or known issues associated with each release. Test patching in a non-production environment to ensure compatibility with your deployment.

Detection guidance

Monitor MOVEit Transfer process memory utilization and system resource consumption for unexpected growth patterns, particularly following interactions with the Custom Reports module. Check application logs for error messages related to memory allocation failures or service crashes. Network IDS/IPS rules targeting Custom Reports endpoints may help detect exploitation attempts. Establish baseline metrics for normal memory usage and alert on sustained anomalies that could indicate the memory leak being triggered.

Why prioritize this

This vulnerability merits immediate attention due to its network-accessible, unauthenticated exploitation path and direct impact on service availability. While not currently listed on the CISA KEV catalog, the ease of exploitation and the critical role MOVEit Transfer often plays in enterprise data workflows justify prioritizing patching within your standard change management process. Organizations should plan upgrades in their next maintenance window.

Risk score, explained

The CVSS 3.1 score of 7.5 (HIGH) reflects the combination of network accessibility (AV:N), low attack complexity (AC:L), no privilege requirements (PR:N), no user interaction (UI:N), and high impact on availability (A:H). Although confidentiality and integrity are not affected, the ability to remotely crash the service without authentication represents a significant operational risk. The score appropriately reflects the ease and impact of exploitation.

Frequently asked questions

Is this vulnerability being actively exploited in the wild?

As of the publication date, this vulnerability is not tracked on the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the ease of exploitation—no authentication, no user interaction required—means organizations should not delay patching. Monitor threat intelligence feeds for any indicators that exploitation has begun.

Can we disable the Custom Reports module as a temporary mitigation?

If your organization does not depend on the Custom Reports functionality, disabling or restricting access to those endpoints may reduce exposure while you plan and execute patching. However, this should be considered a temporary workaround, not a permanent fix. Consult Progress documentation and your deployment configuration to safely disable the feature.

What is the difference between versions 2025.0.x, 2025.1.x, and 2026.0.x, and do we need to stay on the same line?

Progress maintains multiple version branches concurrently. You are not required to jump branches; patching to the latest version in your current line (2025.0.8, 2025.1.4, or 2026.0.1 respectively) will address this vulnerability. Planning major version upgrades can be handled separately as part of your regular lifecycle management.

Will patching this vulnerability require downtime?

Most security patches require at least a service restart. Confirm the downtime impact and any dependencies with Progress's release notes and your internal MOVEit deployment team before scheduling the upgrade. Plan maintenance during a low-traffic window if possible.

This analysis is provided for informational purposes to help security teams prioritize remediation efforts. The vulnerability details are derived from public sources including the CVE record and Progress vendor advisories. Organizations must verify all technical claims, affected version numbers, and patch availability against the official Progress MOVEit Transfer security advisory before taking action. SEC.co and its authors make no warranty regarding the completeness or accuracy of this analysis and disclaim liability for decisions made based on this content. Always test patches in a non-production environment and follow your organization's change management procedures before deploying to production systems. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).