MOVEit Transfer SQL injection
The durable lesson is asset ownership. A highly exposed managed-transfer service can concentrate business-critical data behind a small administration surface, so vulnerability response starts with knowing every deployed instance and its external…
- Original severity
- critical; CVSS 9.8 source-reported; not rescored by vulns.co
- Public source
- github advisory
- Program / vendor
- Progress Software
- Product / surface
- MOVEit Transfer managed file-transfer application
- Weakness
- SQL injection · CWE-89
- Affected boundary
- external request-to-database boundary
- Disclosure date
- 2023-06-02
- Public status checked
- 2026-09-10
What the evidence established
The public advisory describes an injection flaw in an internet-facing file-transfer product, requiring affected instances to be identified and remediated.
Why the impact was credible
The source rates the issue Critical with CVSS 9.8; the affected surface commonly handles sensitive organizational files.
Durable engineering lesson
The durable lesson is asset ownership. A highly exposed managed-transfer service can concentrate business-critical data behind a small administration surface, so vulnerability response starts with knowing every deployed instance and its external reachability. The record preserves the public classification and defensive lesson without republishing attack instructions.
Control pattern
Apply the vendor fix, remove unnecessary public exposure, rotate and review credentials or data only under an incident-response plan, and keep a current asset inventory.
Primary public disclosure
Upstream availability and wording can change. Public status was last checked 2026-09-10.