AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-11903

HIGH · CVSS 8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability in Progress MOVEit Transfer's Ad Hoc module allows for improper neutralization of input during web page generation, leading to a cross-site scripting (XSS) risk. This could enable attackers to execute arbitrary scripts in the context of a user's session, potentially compromising sensitive data and user accounts. Organizations using affected versions of MOVEit Transfer should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-11903
Severity
HIGH
CVSS
8
EPSS
0.28%

Original NVD Description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8.

Related CVEs

Other vulnerabilities affecting the same vendor(s)