Progress vendor intelligence
Progress Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Progress products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 17
- Known exploited vulnerabilities affecting Progress products
- In CISA KEV
- 11
- Records also listed in the official catalog
- Beyond CISA KEV
- 6
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 1
- Progress KEV with sensor-observed exploitation activity
The catalog gap matters for Progress exposure
Six of the seventeen exploited Progress CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 35% of this vendor portfolio.
- 65%
- Covered by CISA
- 35%
- Beyond CISA
- 10
- Product families
Attested Progress CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-2699
EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC) |
ShareFile Storage Zones Controller | High | Beyond CISA | 10 Jul 2026 |
|
CVE-2026-8037
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF |
LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF | Confirmed | In CISA | 01 Jul 2026 |
|
CVE-2024-6671
WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability |
WhatsUp Gold | High | Beyond CISA | 04 Jun 2026 |
|
CVE-2025-8868
Chef Automate compliance service SQL Injection Vulnerability |
Chef Automate | High | Beyond CISA | 27 Oct 2025 |
|
CVE-2024-2389
Flowmon Unauthenticated Command Injection Vulnerability |
Flowmon | High | Beyond CISA | 26 Jun 2025 |
|
CVE-2023-36934
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4... |
MOVEit Transfer | High | Beyond CISA | 27 Jun 2025 |
|
CVE-2017-9248
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect... |
Telerik UI for ASP.NET AJAX | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-18935
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is... |
Telerik UI for ASP.NET AJAX | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-11317
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows... |
Telerik UI for ASP.NET AJAX | Confirmed | In CISA | 11 Apr 2022 |
|
CVE-2017-11357
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to... |
Telerik UI for ASP.NET AJAX | Confirmed | In CISA | 26 Jan 2023 |
|
CVE-2023-34362
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL... |
MOVEit Transfer | Confirmed | In CISA | 02 Jun 2023 |
|
CVE-2023-40044
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability |
WS_FTP Server | Confirmed | In CISA | 05 Oct 2023 |
|
CVE-2024-4358
Registration Authentication Bypass Vulnerability |
Telerik Report Server | Confirmed | In CISA | 13 Jun 2024 |
|
CVE-2024-6670
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability |
WhatsUp Gold | Confirmed | In CISA | 16 Sep 2024 |
|
CVE-2024-1212
LoadMaster Pre-Authenticated OS Command Injection |
LoadMaster | Confirmed | In CISA | 18 Nov 2024 |
|
CVE-2024-4885
WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability |
WhatsUp Gold | Confirmed | In CISA | 03 Mar 2025 |
|
CVE-2024-5806
MOVEit Transfer Authentication Bypass Vulnerability |
MOVEit Transfer | High | Beyond CISA | 25 Jun 2024 |
No Progress CVEs match this search or filter.
Showing 17 of 17 Progress known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, deserialization, and neutralization account for nine mapped occurrences across this Progress KEV portfolio.
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-502
Deserialization of Untrusted Data
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-287
Improper Authentication
CWE-290
Authentication Bypass by Spoofing
CWE-326
Inadequate Encryption Strength
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-522
Insufficiently Protected Credentials
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.