---
schema_version: "secwatch.filing_event.v1"
accession: "0000876167-23-000113"
form_type: "8-K"
ticker: "PRGS"
cik: "0000876167"
company_name: "PROGRESS SOFTWARE CORP /MA"
filed_at: "2023-06-05T23:59:59+00:00"
generated_at: "2026-06-14T07:45:01.957239+00:00"
event_type: "cyber"
sentiment: "negative"
materiality_score: 0.4
calibrated_materiality_score: 0.4
confidence: "high"
source: SEC EDGAR
---

# Progress Software discloses zero-day vulnerability in MOVEit Transfer

## Summary
- On May 28, 2023, Progress learned of unusual activity in MOVEit Transfer, discovering a zero-day vulnerability allowing unauthorized escalated privileges.
- Progress notified customers and took down MOVEit Cloud on May 30, releasing patches for all supported versions on May 31.
- MOVEit Transfer and MOVEit Cloud accounted for less than 4% of Progress' annual gross revenue as of May 31, 2023.
- Progress engaged outside cybersecurity experts and federal law enforcement; does not currently believe the vulnerability will materially impact business or financial results.

## SEC filing metadata
- accession: 0000876167-23-000113
- form_type: 8-K
- ticker: PRGS
- cik: 0000876167
- company_name: PROGRESS SOFTWARE CORP /MA
- filed_at: 2023-06-05T23:59:59+00:00
- event_type: cyber
- sentiment: negative
- materiality_score: 0.4
- calibrated_materiality_score: 0.4
- confidence: high
- sec_items: 8.01, 9.01
- EDGAR index: https://www.sec.gov/Archives/edgar/data/876167/000087616723000113/0000876167-23-000113-index.htm
- EDGAR primary document: https://www.sec.gov/Archives/edgar/data/876167/000087616723000113/prgs-20230530.htm

## Machine-readable alternates
- HTML: https://secwatch.observer/filing/0000876167-23-000113
- JSON: https://secwatch.observer/filing/0000876167-23-000113.json
- Plain text: https://secwatch.observer/filing/0000876167-23-000113.txt

This AI-assisted summary is a reading aid. Review the linked SEC EDGAR filing before relying on any specific claim.
