CyberRota Analysis
AI-GeneratedA vulnerability in Progress MOVEit Transfer allows for a permissive cross-domain security policy, potentially exposing sensitive data to untrusted domains. This high-severity issue could lead to unauthorized access and data leakage, making it critical for organizations using affected versions prior to 2025.1.5 and between 2026.0.0 and 2026.0.3 to prioritize remediation efforts.
CVE
CVE-2026-15966
Severity
HIGH
CVSS
7.5
EPSS
0.20%
Original NVD Description
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
Related CVEs
Other vulnerabilities affecting the same vendor(s)