A vulnerability marked as problematic has been reported in Progress MOVEit Transfer up to 2025.1.4/2026.0.2. Affected is an unknown function. The manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is traded as CVE-2026-15966. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.