Known Vulnerabilities for MOVEit WAF by Progress Software
Listed below are 10 of the newest known vulnerabilities associated with "MOVEit WAF" by "Progress Software".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-59690 json | A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manage... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-59689 json | An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Man... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-59688 json | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manage... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-59687 json | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manage... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-59686 json | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manage... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-15968 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfe... | Not Provided | 2026-07-23 | 2026-07-24 |
| CVE-2026-15967 json | Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1... | Not Provided | 2026-07-23 | 2026-07-25 |
| CVE-2026-15966 json | Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects... | Not Provided | 2026-07-23 | 2026-07-25 |
| CVE-2026-11903 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfe... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-10699 json | Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules). This ... | Not Provided | 2026-07-08 | 2026-07-08 |