May 302023Jun 2Jun 5Jun 8Jun 11Jun 14Jun 17Jun 20Jun 23Jun 26Jun 29Jul 2Jul 5Jul 8Jul 11Jul 1420%30%40%50%60%70%80%90%100%
CVE_2023_34362CVE_2023_35036CVE_2023_35708CVE_2023_3693XFigure 1: Maximum Count of Vulnerable Organizations as % of Organizations using MOVEit Transfer at time of Announcement Dotted red lines represent announcement dates for CVE-2023-34362, CVE-2023-35036, CVE-2023-35708, and CVE-2023-3693X (left to right). Bitsight scans started on June 8th, therefore the 100% initial value is an assumption that all organizations using MOVEit instances were vulnerable on May 31st. However, subsequent initial values (values lying on dotted red lines) reflect the observed number of organizations identified as vulnerable as a percentage of organizations using MOVEit on that day. I.e., roughly 95% of organizations identified as using MOVEit instances on June 9th were vulnerable to CVE-2023-35036; this value is less than 100% because by the time of our scan on the announcement date of CVE-2023-35036, some organizations have already remediated the vulnerability.