CVE detail
CVE-2023-36933
In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception. Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
Progress Software could be staring at fresh litigation over the explosive zero-day found in its file-transfer service, MOVEit, which affected millions of end users globally. The latest probe comes from the US Security and Exchange Commission (SEC), which is seeking information related to the mass hack. “On October 2, 2023, Progress received a subpoena from […]
newswww.csoonline.comOct 12, 2023, 11:43 AMThis threat brief details the critical vulnerability CVE-2023-34362 found in MOVEit Transfer and includes Unit 42's observations, the current attack scope and interim guidance.
vendorunit42.paloaltonetworks.comOct 4, 2023, 1:00 PMIndustry leaders across cybersecurity, networking, and service providers have formed the Network Resilience Coalition, a new alliance focused on securing data and networks that support global economic and national security. Its key aim is to help improve network hardware and software resilience on a global scale, bringing together infrastructure vendors/major network operators experienced in deploying […]
newswww.csoonline.comJul 25, 2023, 3:00 PMThe number of organizations vulnerable to data leaks because of security vulnerabilities in MOVEit Transfer software has dropped significantly with at least 77% of the initially affected organizations no longer susceptible, according to research by Bitsight. Progress, the developer of MOVEit, published an advisory alerting of a critical vulnerability in its MOVEit Transfer product on […]
newswww.csoonline.comJul 24, 2023, 11:49 AMProgress released security patches for a new critical SQL injection vulnerability affecting its MOVEit Transfer software. Progress is informing customers of a new critical SQL injection vulnerability, tracked as CVE-2023-36934, in its MOVEit Transfer software. MOVEit Transfer software recently made the headlines due to the massive Clop ransomware hacking campaign exploiting a vulnerability in the […]
newssecurityaffairs.comJul 7, 2023, 4:49 PMFacing ransomware zero-days, Progress Software will release regular service packs to help customers mitigate critical security flaws.
newswww.securityweek.comJul 7, 2023, 4:02 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-59952CVSS 6.9 · Medium
Valibot helps validate data using a schema. Versions prior to 1.4.2 can throw a TypeError inside its flatten() helper when validation issues contain attacker-controlled object key…
- CVE-2026-42792CVSS 6.3 · Medium
Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemo…
- CVE-2026-48036CVSS 8.4 · High
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in…
- CVE-2026-16730CVSS 5.5 · Medium
A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, ca…
- CVE-2026-62994CVSS 3.7 · Low
CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreDNS zone can trigger a panic when CoreDNS is configured with…
- CVE-2026-59162CVSS 6.9 · Medium
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks onl…