This section outlines issues tracked and fixed by the MOVEit product team for the 2025.1.6 Service Pack.
Note: See the What's New section for a broader summary of features and improvements.

ID

Category

Fixed Issue

88553 WebUI, Security Improved authentication token storage.
106021 Server, Security Improved memory management.
106057 Server, Security Fixed issue where server retains cookie state for incomplete session.
106062 Server, Security Improved dataflow and handling of tenant bindings.
106065 Server, Security Improved dataflow and logic of auth source test.
106066 Custom Notification, Security Improved argument validation and value handling for Custom Notifications.
106067 Permissions, Security Removed unnecessary Custom Report columns for Audit Users.
106159,109114, 106279 WebUI, Security Better tracking of regular users with folder access when public-links available.
106187 REST API, Security Removed visible/unneeded public link data fields.
106310 WebUI, Permissions Fixed issue that resulted in "Invalid Folder ID" error and no Folders tab displaying.
106534 Ad Hoc Fixed issue where unexpected characters in reply field cause NullReferenceException.
107347 Key Service Exceptions from KeyManagementService not logged at expected log level.
107480 Ad Hoc, Security Improved handling of user address book lookups.
107483,107802,108940,109708, Reports, Security Additional custom report SQL validation and logic constraints applied for Audit Users and report engine.
107520 Certificate, Security Improved client certificate handling to prevent users from blocking access with a self-signed certificate.
107614 SSO/SAML, security Fixed issue where SAML sign-on could resolve to a same-name user.
107616 Users, Security Fixed inheritance issue for GroupAdmin cloning scenario.
107619 Ad Hoc, Security Fixed issue where package recall did not prevent attachment download by recipient.
107696 Server, Security Updated 7-Zip dependency to 26.02.
107713 Audi Log, Security Improved Audit Log request validation.
107787 Audit Log, Security Fixed issue where Admin could delegate audit log cleanup to Regular User.
107834 REST API, Security Improved argument and value handling for Folders endpoint.
107837 MySQL, Security Updated MySQL dependency to 8.4.11.
107838 Ad Hoc, Security Fixed issue where Guest User could create package using different organization.
108017 Installer, Upgrade Fixed issue where upgrade to 18.0.4.x fails with message CreateTables: Error running SQL script...CREATE VIEW must be the first statement.
108110 Certificate, Security Improved controls for sessions that use specific client-certificate bindings.
108111 REST API, Shared Folders, Security Fixed issue where owner can grant implicit write and delete permissions to Shared Folder.
108118 REST API, Security Applied stricter shared folder and file permission model for users with Write+List to prevent renaming.
108269 SSO, Security Improved user management and session controls for OAuth users.
108282 FTPS Fixed FTPS TLS handshake failure with certain client-specific MTU scenarios.
108292 Installer, Upgrade Fixed issue where services crash with MC_ERROR_DISABLED after upgrade where specific files were locked during upgrade.
108406 Database, Security Improved query building and validation..
108491 Installer Fixed case where silent install of MOVEit Transfer with SMTP OAuth ignores response file's EmailServer/EmailPort.
108702 MySQL, Installer Fixed issue where SslMode=none no longer accepted by MySQL .NET connector.
108983 HTTP, WebUI Fixed issue where stale Referrer-Policy setting could prevent sign-on attempts.
109079 Settings (org), Security Fixed issue where user can change default or existing package classification.
109118 Security, UI Fixed header-parser desync for machine endpoint.
109239 Uploader, MOVEit Automation Fixed issue that occurs if MIA download from MIT misses first 100MB chunk if MIT folder has immediate sender notifications enabled
109329 Certificate, LDAP Fixed issue where client cert-only sign-on fails under External Only authentication policy.
109476 Reports, Security Fixed issue in Org Admin Custom Report generator to prevent access to concurrent admin sessions.
109571 SSO/SAML, Security Fixed issue where authenticated user could overwrite SAML Federation Metadata.