logo

CVE-2023-34362 RCE vulnerability in MOVEit Transfer exploited in the wild: everything you need to know

ID: 218c2093-1fe2-5406-8774-c0dbcf53dc3c

STIX ID: report--218c2093-1fe2-5406-8774-c0dbcf53dc3c

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2023-06-04

Date Updated: 2026-05-01

...
...

Progress disclosed multiple critical vulnerabilities in MOVEit Transfer (including CVE-2023-34362 and later CVEs) that allow unauthenticated SQL injection/RCE against the application; these flaws were actively exploited in the wild, with the Cl0p ransomware group claiming responsibility and multiple organizations publicly disclosing compromise and data exfiltration. Progress published fixed versions and guidance; the report recommends immediate patching, restricting public HTTP access, rotating compromised cloud/database credentials, and using vendor advisories and threat center queries to identify exposed instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.