CVE-2026-15966: Improper CORS handling in MOVEit Transfer
Published Jul 23, 2026
·Updated
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
Affected Software
3 affected components
Progress MOVEit Transfer<2025.1.5, >2026.0.0<=2026.0.3
Progress MOVEit Transfer<2025.1.5
Progress MOVEit Transfer>=2026.0.0<2026.0.3
Event History
Jul 23, 2026
CVE Published
via MITRE·07:58 PM
Data Sourced
via MITRE·07:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-15966?
The severity of CVE-2026-15966 is rated high with a score of 7.5.
2
How do I fix CVE-2026-15966?
To fix CVE-2026-15966, upgrade Progress MOVEit Transfer to version 2026.0.3 or later.
3
What impact does CVE-2026-15966 have on my system?
CVE-2026-15966 allows for improper CORS handling, risking unauthorized access to sensitive data.
4
Which versions of Progress MOVEit Transfer are affected by CVE-2026-15966?
CVE-2026-15966 affects Progress MOVEit Transfer versions before 2025.1.5 and from 2026.0.0 to 2026.0.2.
5
Is CVE-2026-15966 related to cross-site request forgery?
CVE-2026-15966 is not directly related to cross-site request forgery, but it pertains to improper CORS handling, which can lead to similar vulnerabilities.