Progress Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Progress products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
17
In CISA KEV
10
Beyond CISA KEV
7
Sensor Observed
1
Virtual Patch Available
2
Progress KEVs Added by Year
17 Progress KEVs added all time (primary attestation date).
Attested CVEs
Filter full feed by Progress| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-2699
EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC) |
ShareFile Storage Zones Controller | High | Not in CISA | 10 Jul 2026 |
|
CVE-2026-8037
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF |
LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF | Confirmed | Not in CISA | 01 Jul 2026 |
|
CVE-2024-6671
WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability |
WhatsUp Gold | High | Not in CISA | 04 Jun 2026 |
|
CVE-2025-8868
Chef Automate compliance service SQL Injection Vulnerability |
Chef Automate | High | Not in CISA | 27 Oct 2025 |
|
CVE-2024-2389
Flowmon Unauthenticated Command Injection Vulnerability |
Flowmon | High | Not in CISA | 26 Jun 2025 |
|
CVE-2023-36934
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4... |
MOVEit Transfer | High | Not in CISA | 27 Jun 2025 |
|
CVE-2017-9248
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect... |
Telerik UI for ASP.NET AJAX | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-18935
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is... |
Telerik UI for ASP.NET AJAX | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-11317
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows... |
Telerik UI for ASP.NET AJAX | Confirmed | In CISA | 11 Apr 2022 |
|
CVE-2017-11357
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to... |
Telerik UI for ASP.NET AJAX | Confirmed | In CISA | 26 Jan 2023 |
|
CVE-2023-34362
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL... |
MOVEit Transfer | Confirmed | In CISA | 02 Jun 2023 |
|
CVE-2023-40044
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability |
WS_FTP Server | Confirmed | In CISA | 05 Oct 2023 |
|
CVE-2024-4358
Registration Authentication Bypass Vulnerability |
Telerik Report Server | Confirmed | In CISA | 13 Jun 2024 |
|
CVE-2024-6670
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability |
WhatsUp Gold | Confirmed | In CISA | 16 Sep 2024 |
|
CVE-2024-1212
LoadMaster Pre-Authenticated OS Command Injection |
LoadMaster | Confirmed | In CISA | 18 Nov 2024 |
|
CVE-2024-4885
WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability |
WhatsUp Gold | Confirmed | In CISA | 03 Mar 2025 |
|
CVE-2024-5806
MOVEit Transfer Authentication Bypass Vulnerability |
MOVEit Transfer | High | Not in CISA | 25 Jun 2024 |
Common Vulnerability Classes (CWE)
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 5
- CWE-502 — Deserialization of Untrusted Data 2
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
- CWE-287 — Improper Authentication 1
- CWE-290 — Authentication Bypass by Spoofing 1
- CWE-326 — Inadequate Encryption Strength 1
- CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1
- CWE-522 — Insufficiently Protected Credentials 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology