CVE-2026-10699: Memory leak in SFTP service can result in a denial of service in MOVEit Transfer
Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules).
This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress MOVEit Transferto a version that resolves this vulnerability.Fixed in 2025.0.8 - Upgrade
Upgrade
Progress MOVEit Transferto a version that resolves this vulnerability.Fixed in 2025.1.4 - Upgrade
Upgrade
Progress MOVEit Transferto a version that resolves this vulnerability.Fixed in 2026.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10699?
The severity of CVE-2026-10699 is high with a score of 7.5.
How does CVE-2026-10699 affect MOVEit Transfer?
CVE-2026-10699 can lead to a denial of service due to a memory leak in the SFTP service.
Which versions of MOVEit Transfer are affected by CVE-2026-10699?
CVE-2026-10699 affects MOVEit Transfer versions from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, and from 2026.0.0 before 2026.0.1.
How can I mitigate the risk of CVE-2026-10699?
To mitigate the risk of CVE-2026-10699, it is recommended to upgrade MOVEit Transfer to a fixed version.
What type of vulnerability is CVE-2026-10699 classified as?
CVE-2026-10699 is classified as a memory leak vulnerability.