Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Progress Releases Patch for MOVEit Transfer Resource Consumption Flaw

Progress Software has released security patches to address a high-severity vulnerability in its MOVEit Transfer platform discovered on October 29, 2025.The flaw, tracked as CVE-2025-10932, affects the AS2 module and allows attackers to consume system…

Progress Software has released security patches to address a high-severity vulnerability in its MOVEit Transfer platform discovered on October 29, 2025.The flaw, tracked as CVE-2025-10932, affects the AS2 module and allows attackers to consume system resources without proper restrictions.AttributeDetailsCVE IDCVE-2025-10932Vulnerability TypeUncontrolled Resource Consumption (CWE-400)Affected ComponentProgress MOVEit Transfer AS2 ModuleCVSS Score8.2 (HIGH)This vulnerability puts thousands of enterprise organizations at risk, particularly those relying on MOVEit Transfer for secure file exchange and data management operations.The vulnerability received a CVSS severity score of 8.2, categorizing it as a high-risk threat that requires immediate attention.Unlike some other critical flaws, this particular issue does not require authentication or user interaction, meaning attackers can exploit it remotely with minimal barriers to entry.Progress Software moved quickly to address the issue by releasing patched versions and implementing temporary protective measures for customers who cannot immediately update their systems.Understanding the Vulnerability and Its ImpactThe uncontrolled resource consumption flaw impacts the AS2 module within MOVEit Transfer, a widely-used file transfer solution trusted by financial institutions, healthcare providers, and government agencies.The vulnerability allows an attacker to send specially crafted requests that consume excessive server resources, potentially leading to service degradation or complete system unavailability.This type of attack, known as a denial-of-service vulnerability, can disrupt critical business operations and interrupt important file transfer workflows.Multiple versions of MOVEit Transfer remain vulnerable to this attack. Progress has confirmed that versions ranging from 2025.0.0 through 2025.0.2, 2024.1.0 through 2024.1.6, and 2023.1.0 through 2023.1.15 all contain the flaw.Organisations running any of these versions should treat this update as a priority security matter.Progress released patched versions that implement IP address whitelisting to protect the AS2 module from unauthorized access.Organizations using MOVEit Transfer have two primary options depending on their operational requirements.Customers with current maintenance agreements can download the fixed versions directly from the Progress Download Center using their credentials. These include MOVEit Transfer 2025.0.3, 2024.1.7, and 2023.1.16 for respective version branches.For organizations unable to immediately deploy patches, Progress recommends temporarily disabling the AS2 module by removing specific files from the installation directory.This interim solution protects systems while organizations plan their update schedules. Alternatively, administrators can add IP addresses of trusted AS2 trading partners to a whitelist, limiting exposure until patches are installed.Progress MOVEit Cloud customers require no action, as the company has already upgraded those cloud-hosted instances to the patched version. Organizations running on-premises installations must take active steps to secure their systems against this threat.Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Based on reporting by GBHackers.

Advertisement
AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories