Progress Software vendor intelligence

Progress Software Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Progress Software products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
9
Known exploited vulnerabilities affecting Progress Software products
In CISA KEV
6
Records also listed in the official catalog
Beyond CISA KEV
3
Additional exploited CVEs absent from CISA KEV
Sensor Observed
1
Progress Software KEV with sensor-observed exploitation activity

The catalog gap matters for Progress Software exposure

Three of the nine exploited Progress Software CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss one-third of this vendor portfolio.

67%
Covered by CISA
33%
Beyond CISA
7
Product families

Attested Progress Software CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-8037

OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF

LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF Confirmed In CISA 01 Jul 2026
CVE-2024-6671

WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability

WhatsUp Gold High Beyond CISA 04 Jun 2026
CVE-2025-8868

Chef Automate compliance service SQL Injection Vulnerability

Chef Automate High Beyond CISA 27 Oct 2025
CVE-2024-2389

Flowmon Unauthenticated Command Injection Vulnerability

Flowmon High Beyond CISA 26 Jun 2025
CVE-2023-40044

WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability

WS_FTP Server Confirmed In CISA 05 Oct 2023
CVE-2024-4358

Registration Authentication Bypass Vulnerability

Telerik Report Server Confirmed In CISA 13 Jun 2024
CVE-2024-6670

WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability

WhatsUp Gold Confirmed In CISA 16 Sep 2024
CVE-2024-1212

LoadMaster Pre-Authenticated OS Command Injection

LoadMaster Confirmed In CISA 18 Nov 2024
CVE-2024-4885

WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability

WhatsUp Gold Confirmed In CISA 03 Mar 2025

Showing 9 of 9 Progress Software known exploited vulnerabilities.

Recurring weakness patterns

Neutralization, neutralization, and authentication bypass by spoofing account for six mapped occurrences across this Progress Software KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.