logo

MOVEit Transfer Zero-Day: What We Know So Far

ID: a8644470-4d65-57d8-9503-d3879fbd227b

STIX ID: report--a8644470-4d65-57d8-9503-d3879fbd227b

Feed Name: ReliaQuest Blog

Threat Score
85/100

Date Published: 2023-06-01

Date Updated: 2026-04-29

...
...

## Executive Summary ReliaQuest reports a critical SQL injection vulnerability (CVE-2023-34362) in MOVEit Transfer discovered May 31, 2023 and observed exploited in the wild since at least May 27, 2023; successful exploitation can allow SQL execution, privilege escalation, and data exfiltration across multiple affected MOVEit versions, and the advisory provides immediate mitigations (disable HTTP/HTTPS, apply vendor patches, backup systems) and detection/hunting actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.