Progress MOVEit Transfer Memory Leak Vulnerability Leading to Denial-of-Service

Vulnerability

A memory leak vulnerability has been identified in the SFTP service of Progress MOVEit Transfer, specifically within the Custom Reports modules. This issue affects MOVEit Transfer versions 2024.1.8 and earlier, 2025.0.0 prior to 2025.0.8, 2025.1.0 prior to 2025.1.4, and 2026.0.0 prior to 2026.0.1. The vulnerability arises from improper memory management, allowing for a gradual exhaustion of memory resources on the server. As a result, the vulnerability can cause a temporary denial-of-service condition, disrupting normal service operations.

Impact

Exploitation of this vulnerability leads to a memory leak that can exhaust server resources, causing a temporary denial-of-service condition where the MOVEit Transfer service becomes unresponsive or unavailable.

Remediation

Users are advised to upgrade to MOVEit Transfer versions 2026.0.1, 2025.1.4, or 2025.0.8. For those on MOVEit Cloud, no action is required as the environment has already been updated to a patched version.

Added: Jul 8, 2026, 5:03 PM
Updated: Jul 8, 2026, 5:03 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
7.6
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.