MOVEit Transfer 2025.1 Leaves Active Support on November 18, 2026
Progress gives each MOVEit Transfer release one year of Active support, and for the 2025.1 release that year runs out on November 18, 2026. The company's own MOVEit Product Support Lifecycle page carries the line as "MOVEit Transfer 2025.1 (17.1)" with three dates under three headings: ACTIVE November 19, 2025, SUNSET November 18, 2026, RETIRED May 19, 2027. Each column is the date a phase begins. The same day is the RETIRED date for the release before it, 2025.0 (17.0), which has been in Sunset since May 20, 2026. So on November 18, 2026 two of the three MOVEit Transfer lines Progress lists stop getting fixes, and one, 2026.0, is left Active.
Every MOVEit Transfer version Progress lists
Progress ships MOVEit Transfer twice a year and names each release by year, with the engineering version in brackets. Its lifecycle page lists three: 2026.0 (18.0), 2025.1 (17.1) and 2025.0 (17.0). Here they are with the three dates from that page as we serve them on the Progress MOVEit Transfer page, plus the date of each line's most recent release from the MOVEit Transfer release notes, and the two 2024 lines that have dropped off Progress's table:
| Version | Status | Active from | Sunset | Retired | Most recent release | Progress phase on the date of this article |
|---|---|---|---|---|---|---|
| 2026.0 (18.0) | Supported | May 20, 2026 | May 19, 2027 | November 17, 2027 | September 24, 2026 | Active |
| 2025.1 (17.1) | Approaching | November 19, 2025 | November 18, 2026 | May 19, 2027 | September 24, 2026 | Active, Sunset in November |
| 2025.0 (17.0) | Approaching | May 21, 2025 | May 20, 2026 | November 18, 2026 | June 22, 2026 | Sunset, Retired in November |
| 2024.1 (16.1) | EOL | November 20, 2024 | Not listed | Not listed | November 17, 2025 | Retired (not in the table) |
| 2024.0 (16.0) | EOL | May 22, 2024 | Not listed | Not listed | March 19, 2025 | Retired (not in the table) |
Three notes on the table. First, the Status column is the site's generic badge (Supported, Approaching, EOL), computed from the Retired date at every build; the last column is Progress's own phase name on the day this was written. Second, the two 2024 lines carry no Sunset or Retired date because Progress prints none: they are simply absent from the lifecycle table, and the page's note covers that case, "Releases not listed in the table below are considered Retired." We serve them as Retired without a date. Third, the 2025.0 line's most recent release is dated June 22, 2026, a month after its Sunset date of May 20, 2026. The release notes list it as a hotfix. Progress's own policy says the determination of whether a service pack or hot fix is available "is at Progress' discretion", so a post-Sunset hotfix is possible under the policy; it is not something the policy promises, and nothing newer has shipped for 2025.0 since.
The pattern is one year of Active, six months of Sunset, then Retired. Both Active lines are still taking releases on the same day: 2025.1's most recent is dated September 24, 2026 and 2026.0's September 24, 2026. That is what the Active phase looks like from the outside; Progress says service packs are targeted at a bi-monthly cadence. The cadence stops for 2025.1 on its Sunset date.
MOVEit Automation, EZ, Xfer and Gateway: the same calendar
The lifecycle page lists the rest of the MOVEit family on the same three-phase model, and the server-side products share the server's dates. MOVEit Automation's three listed versions as we serve them on the Progress MOVEit Automation page:
| Version | Status | Active from | Sunset | Retired | Most recent release |
|---|---|---|---|---|---|
| 2026.0 (18.0) | Supported | May 20, 2026 | May 19, 2027 | November 17, 2027 | October 6, 2026 |
| 2025.1 (17.1) | Approaching | November 19, 2025 | November 18, 2026 | May 19, 2027 | October 6, 2026 |
| 2025.0 (17.0) | Approaching | May 21, 2025 | May 20, 2026 | November 18, 2026 | May 22, 2026 |
The page also lists the MOVEit EZ and MOVEit Xfer clients at 2026.0, 2025.1 and 2025.0 with the same three dates as the server, and MOVEit Gateway at 2026.0 (8.0) and 2025.0 (7.0), the Gateway 2025.0 line Retired on the same November date as Transfer 2025.0. We do not serve the clients or Gateway as separate products; the dates above are the ones to plan a MOVEit estate around, and a Transfer upgrade is normally paired with the Automation, client and Gateway versions from the same release.
Active, Sunset, Retired: the three phases as Progress defines them
Progress uses the same three-phase model across its product lines (its WS_FTP Server page reads the same way), and the MOVEit lifecycle page spells each phase out. Paraphrasing the page, read in the browser on October 11, 2026, with Progress's own key phrases quoted:
Active. Technical support and product updates for customers under warranty or a current service agreement. Three release types: major versions, which "require an updated license file or must be activated on-line before they can be used"; service packs, which bundle corrections for multiple security and product defects and are "targeted to be delivered on a bi-monthly release cadence"; and hot fixes, targeted corrections delivered as needed, whose deployment "will require the most recent service pack for the targeted major version". The Active phase starts when a major version is first made available for download on the Progress Community.
Sunset. Technical support continues under the same terms, but "No service packs or hot fixes are provided for versions of the product in the sunset phase." Progress does not develop features for the version and will advise migration to a newer version if that resolves the reported issue. Sunset "begins the day after Active phase ends."
Retired. Technical support is "best effort" and may require upgrading to the current version to resolve a known issue; "No product updates are provided for this version of the product." Online help and Knowledge Base content stay available. Retired begins the day after Sunset ends.
The practical difference between Sunset and Retired is small for a security team and large for a help desk. In both phases the policy provides no service packs and no hot fixes. In Sunset you can still log a case and get an answer; in Retired the answer is best effort and may be "upgrade". In every phase the page repeats that Progress strongly recommends upgrading to the most current version and reserves the right to require it to resolve an issue.
Where a 2025.x server goes
To MOVEit Transfer 2026.0 (18.0), the only line Progress lists that stays Active after November 18. Its dates on the lifecycle page as we serve them:
| Version | Active from | Sunset | Retired |
|---|---|---|---|
| 2026.0 (18.0) | May 20, 2026 | May 19, 2027 | November 17, 2027 |
A server moved to 2026.0 now is inside Active until May 19, 2027 and Retired on November 17, 2027. Two things on the lifecycle page bear on the move itself. New major versions need an updated license file or online activation, and Progress says updated license files are only provided for licenses covered by a current service agreement. So the upgrade is also a licensing check: a lapsed agreement means no activation for 2026.0, and under the Sunset terms no fixes for 2025.1 either. And on a twice-yearly release train with one-year Active phases, 2026.0 itself is Active for only six more months after 2025.1's Sunset date. The next release, whatever Progress names it, is the one a 2025.x estate should expect to land on within a year of moving.
The exploitation record: 2023 and what it says about 2026
MOVEit Transfer has 1 entry in CISA's Known Exploited Vulnerabilities catalog, and 1 KEV entry for the product carries CISA's known-ransomware-campaign-use flag. The entry is CVE-2023-34362, which CISA names "Progress MOVEit Transfer SQL Injection Vulnerability" (CWE-89), added to the catalog on June 2, 2023 with a federal due date of June 23, 2023. CISA's description, verbatim: "Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements." Its required action: "Apply updates per vendor instructions." Its knownRansomwareCampaignUse field reads "Known". The entry's notes point to CISA's joint advisory AA23-158a, which the FBI and CISA titled "#StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability" and which states that, according to open source information, exploitation began on May 27, 2023. The notes also cite Progress's own advisory from the same week.
Every MOVEit Transfer version that was current in 2023 is now Retired under Progress's "not listed" rule; the flaw itself was fixed in the 2023 patches and does not affect the lines in the table above. It is here because of what it showed: a MOVEit Transfer server is a box that exists to accept files from outside the organisation, usually reachable from the internet, with a database behind it, and in 2023 a flaw in it was being exploited for days before the vendor published a fix. That is the profile that puts the product on our EOS Edge Device List alongside its stablemate WS_FTP Server. The next flaw of this kind gets a service pack or hot fix on the lines in Active. Under the terms quoted above, a 2025.1 server after November 18, 2026, or a 2025.0 server today, is told to migrate.
What to do
On 2025.1: plan the move to 2026.0 ahead of November 18, 2026, and check the service agreement first, because 2026.0 needs a license file or activation that Progress only issues to covered licences. The 2025.1 line's most recent release is dated September 24, 2026; be on it before the move, since Progress's hot-fix rule requires the most recent service pack for the targeted major version.
On 2025.0: you are in Sunset already, since May 20, 2026, and Retired on November 18, 2026. The same move to 2026.0, sooner. Treat the server as unpatched for anything disclosed since its last release on June 22, 2026.
On 2024.x or older: Retired by Progress's rule, with no date to point at. Move now, and treat the server as unpatched for anything disclosed since its last release (November 17, 2025 for 2024.1, March 19, 2025 for 2024.0).
On 2026.0: Active until May 19, 2027. Take the bi-monthly service packs as they land; the hot-fix rule means you cannot skip them and still get an emergency fix. Pair the Transfer upgrade with MOVEit Automation 2026.0, which shares the dates.
Everyone: the Progress MOVEit Transfer page and MOVEit Automation page carry every listed version with its Active, Sunset and Retired dates, verified against the lifecycle page and refreshed at every build, so a new release Progress lists shows up there before it shows up here.
Frequently Asked Questions
When does Progress MOVEit Transfer 2025.1 reach end of life?
Progress's MOVEit Product Support Lifecycle page lists MOVEit Transfer 2025.1 (17.1) as Active from November 19, 2025, Sunset from November 18, 2026 and Retired from May 19, 2027. In Progress's own words, no service packs or hot fixes are provided for versions of the product in the Sunset phase, and in the Retired phase no product updates are provided and technical support is best effort.
Is MOVEit Transfer 2025.0 still supported?
Only for technical support, and only until November 18, 2026. MOVEit Transfer 2025.0 (17.0) entered Progress's Sunset phase on May 20, 2026, so it has received no service packs or hot fixes since then, and it is Retired on November 18, 2026, the same day 2025.1 enters Sunset. Versions older than 2025.0 are not in Progress's lifecycle table, and the page says releases not listed are considered Retired.
Which MOVEit Transfer version should a 2025.x server move to?
MOVEit Transfer 2026.0 (18.0), Active since May 20, 2026, with Sunset on May 19, 2027 and Retired on November 17, 2027. It is the only MOVEit Transfer line Progress lists that stays Active after November 18, 2026. Progress strongly recommends upgrading to the most current version, and new major versions need an updated license file or online activation, which Progress provides only for licenses under a current service agreement.
Does MOVEit Automation follow the same dates?
Yes. Progress's lifecycle page lists MOVEit Automation 2026.0, 2025.1 and 2025.0 with the same Active, Sunset and Retired dates as the matching MOVEit Transfer versions: 2025.1 enters Sunset on November 18, 2026 and 2025.0 is Retired that day. The MOVEit EZ and MOVEit Xfer clients and MOVEit Gateway are on the same page with the same pattern.
Related
- Progress MOVEit Transfer — every version with its Active, Sunset and Retired dates
- Progress MOVEit Automation — the automation server on the same calendar
- WS_FTP Server 9.0 leaves Active support — the same vendor's other file transfer server, same three phases
- The EOS Edge Device List — end-of-support status for every internet-facing platform we track
- Exploited & Unpatchable — the feed of KEV entries on products past their fix window
- How we verify our dates — the rules every number on this site is held to