C
月内に
Progress MOVEit Transferにおいて、セキュリティポリシーのバイパスおよび間接的なリモートコード実行(XSS)が可能な複数の脆弱性
📌 一言でいうと
Progress MOVEit Transferにおいて、セキュリティポリシーのバイパスおよび間接的なリモートコード実行(XSS)が可能な複数の脆弱性が発見されました。影響を受けるのはバージョン2026.0.3より前のすべてのバージョンです。ベンダーは修正パッチをリリースしており、速やかな更新が推奨されています。
🔍該当判定
- ファイル転送ソフト「Progress MOVEit Transfer」を社内で利用している
- MOVEit Transferのバージョンが 2026.0.3 より古い
- 外部とのファイル送受信に MOVEit Transfer サーバーを構築して運用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
最新バージョン(2026.0.3以降)へのアップデートを適用してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Progress MOVEit Transfer 脆弱性対応について
お疲れさまです。Progress MOVEit Transferに関する脆弱性情報共有です。
■ 概要
Progress MOVEit Transferにおいて、セキュリティポリシーのバイパスおよび間接的なリモートコード実行(XSS)が可能な脆弱性が報告されました。過去にCl0p等のアクターが同製品の脆弱性を悪用した大規模攻撃を行っているため、迅速な対応が推奨されます。
■ 影響範囲
- 対象製品: Progress MOVEit Transfer
- 対象バージョン: 2026.0.3 未満
■ 対応手順
1. 現在のバージョンを確認してください。
2. ベンダーが提供する最新バージョン(2026.0.3)へアップデートを適用してください。
■ 参考情報
- Progress Security Bulletin 2026.0.3 (2026年7月24日)
- https://docs.progress.com/bundle/moveit-t
対応優先度: 高
対応期限: 速やかに
お疲れさまです。Progress MOVEit Transferに関する脆弱性情報共有です。
■ 概要
Progress MOVEit Transferにおいて、セキュリティポリシーのバイパスおよび間接的なリモートコード実行(XSS)が可能な脆弱性が報告されました。過去にCl0p等のアクターが同製品の脆弱性を悪用した大規模攻撃を行っているため、迅速な対応が推奨されます。
■ 影響範囲
- 対象製品: Progress MOVEit Transfer
- 対象バージョン: 2026.0.3 未満
■ 対応手順
1. 現在のバージョンを確認してください。
2. ベンダーが提供する最新バージョン(2026.0.3)へアップデートを適用してください。
■ 参考情報
- Progress Security Bulletin 2026.0.3 (2026年7月24日)
- https://docs.progress.com/bundle/moveit-t
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Progress MOVEit Transfer Vulnerability Remediation
Dear IT/Security Team,
We are sharing information regarding vulnerabilities discovered in Progress MOVEit Transfer.
■ Overview
Multiple vulnerabilities have been identified that could allow an attacker to bypass security policies and perform indirect remote code execution (XSS). Given the history of high-profile attacks on this product by actors such as Cl0p, immediate patching is critical.
■ Scope
- Product: Progress MOVEit Transfer
- Affected Versions: All versions prior to 2026.0.3
■ Remediation Steps
1. Verify the current version of the installed MOVEit Transfer instance.
2. Apply the latest security update (Version 2026.0.3 or newer).
■ Reference
- Progress Security Bulletin 2026.0.3 (July 24, 2026)
- https://docs.progress.com/bundle/moveit-t
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding vulnerabilities discovered in Progress MOVEit Transfer.
■ Overview
Multiple vulnerabilities have been identified that could allow an attacker to bypass security policies and perform indirect remote code execution (XSS). Given the history of high-profile attacks on this product by actors such as Cl0p, immediate patching is critical.
■ Scope
- Product: Progress MOVEit Transfer
- Affected Versions: All versions prior to 2026.0.3
■ Remediation Steps
1. Verify the current version of the installed MOVEit Transfer instance.
2. Apply the latest security update (Version 2026.0.3 or newer).
■ Reference
- Progress Security Bulletin 2026.0.3 (July 24, 2026)
- https://docs.progress.com/bundle/moveit-t
Priority: High
Deadline: Immediate