Progress Software vendor intelligence
Progress Software Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Progress Software products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 9
- Known exploited vulnerabilities affecting Progress Software products
- In CISA KEV
- 6
- Records also listed in the official catalog
- Beyond CISA KEV
- 3
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 1
- Progress Software KEV with sensor-observed exploitation activity
The catalog gap matters for Progress Software exposure
Three of the nine exploited Progress Software CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss one-third of this vendor portfolio.
- 67%
- Covered by CISA
- 33%
- Beyond CISA
- 7
- Product families
Attested Progress Software CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-8037
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF |
LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF | Confirmed | In CISA | 01 Jul 2026 |
|
CVE-2024-6671
WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability |
WhatsUp Gold | High | Beyond CISA | 04 Jun 2026 |
|
CVE-2025-8868
Chef Automate compliance service SQL Injection Vulnerability |
Chef Automate | High | Beyond CISA | 27 Oct 2025 |
|
CVE-2024-2389
Flowmon Unauthenticated Command Injection Vulnerability |
Flowmon | High | Beyond CISA | 26 Jun 2025 |
|
CVE-2023-40044
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability |
WS_FTP Server | Confirmed | In CISA | 05 Oct 2023 |
|
CVE-2024-4358
Registration Authentication Bypass Vulnerability |
Telerik Report Server | Confirmed | In CISA | 13 Jun 2024 |
|
CVE-2024-6670
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability |
WhatsUp Gold | Confirmed | In CISA | 16 Sep 2024 |
|
CVE-2024-1212
LoadMaster Pre-Authenticated OS Command Injection |
LoadMaster | Confirmed | In CISA | 18 Nov 2024 |
|
CVE-2024-4885
WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability |
WhatsUp Gold | Confirmed | In CISA | 03 Mar 2025 |
No Progress Software CVEs match this search or filter.
Showing 9 of 9 Progress Software known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, neutralization, and authentication bypass by spoofing account for six mapped occurrences across this Progress Software KEV portfolio.
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-290
Authentication Bypass by Spoofing
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-502
Deserialization of Untrusted Data
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.