AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-10698

HIGH · CVSS 7.2 EPSS 0.50%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A vulnerability exists in the Custom Reports modules of Progress MOVEit Transfer, where improper neutralization of special elements in data query logic could allow an attacker to manipulate queries and potentially access sensitive information. Organizations using affected versions (2025.0.0 to 2025.0.8, 2025.1.0 to 2025.1.4, and 2026.0.0 to 2026.0.1) should prioritize patching to mitigate the risk of data exposure and unauthorized access. This issue is particularly critical for enterprises handling sensitive data or regulated information.

CVE
CVE-2026-10698
Severity
HIGH
CVSS
7.2
EPSS
0.50%

Original NVD Description

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)