In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions.
Published: 2023-06-02
Discovery of a new zero-day vulnerability in MOVEit Transfer becomes the second zero-day disclosed in a managed file transfer solution in 2023, with reports suggesting that threat actors have stolen data from a number of organizations.
https://thehackernews.com/2026/08/clop-linked-windchill-web-shell.html
https://reliaquest.com/blog/clop-returns-with-custom-implant-in-mass-extortion-campaign/
https://www.infosecurity-magazine.com/news/automation-vulnerability/
https://www.infosecurity-magazine.com/news/moveit-attack-risk-scanning-surge/
https://thehackernews.com/2025/06/moveit-transfer-faces-increased-threats.html
https://www.databreachtoday.com/scans-probing-for-moveit-systems-may-be-precursor-to-attacks-a-28832
https://www.greynoise.io/blog/surge-moveit-transfer-scanning-activity
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a
https://www.tenable.com/blog/from-bugs-to-breaches-25-significant-cves-as-mitre-cve-turns-25
https://www.tenable.com/blog/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-vulnerability
https://github.com/chengbochuan3/CVE-Enterprise-Software
https://github.com/nkoziel/cve-to-detection-rule
https://github.com/avidzcheetah/CVE-Triage-Patch-agent
https://github.com/umaadi/truepositive-cli
https://github.com/OmarRao/secure-scope
https://github.com/flags-alt/abyss-c2
https://github.com/unknownCyberEnthusiast/cve-cti
https://github.com/THU-HJY/CVE-Honeypot
https://github.com/develku/Incident-Investigation-Portfolio
https://github.com/hermestoola/bb-hunter-pro
https://github.com/chiranths09/Syntecxhub_Project_Vulnerability-CVE-Scanner
https://github.com/tubaaiftikhar-ui/MOVEit-Transfer-Data-Breach-Analysis.
https://github.com/Willie-Conway/SOC-Simulator
https://github.com/JerryT-cell/Container-Security-Risk-Assessment-Pipeline-using-LLMs
https://github.com/Leegreen305/CVE-Threat-Intelligence-Tracker
https://github.com/jiahuiwa731-droid/pii-cve-governance-infrastructure
https://github.com/nethoundsh/shogunhound
https://github.com/khengar9274-web/moveit-transfer-2023-breach
https://github.com/8BitTacoSupreme/sbom_CVE_dash_demo
https://github.com/Hiviexd/cve-tracker
https://github.com/Naveenbana5250/CVE-2023-34362-Defense-Package
https://github.com/cyberleelawat/LeelawatX-CVE-Hunter
https://github.com/xishir/cve-mcp-server
https://github.com/aditibv/MOVEit-CVE-2023-34362
https://github.com/glen-pearson/MoveIT-CVE-2023-34362-RCE
Published: 2023-06-02
Updated: 2026-06-17
Named Vulnerability: MOVEit VulnerabilityNamed Vulnerability: MOVEit TransferNamed Vulnerability: MOVEitKnown Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99934
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored