Progress Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Progress products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

17

In CISA KEV

10

Beyond CISA KEV

7

Sensor Observed

1

Virtual Patch Available

2

Progress KEVs Added by Year

Loading...

17 Progress KEVs added all time (primary attestation date).

CVE Confidence CISA KEV Added
CVE-2026-2699

EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)

High Not in CISA 10 Jul 2026
CVE-2026-8037

OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF

Confirmed Not in CISA 01 Jul 2026
CVE-2024-6671

WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability

High Not in CISA 04 Jun 2026
CVE-2025-8868

Chef Automate compliance service SQL Injection Vulnerability

High Not in CISA 27 Oct 2025
CVE-2024-2389

Flowmon Unauthenticated Command Injection Vulnerability

High Not in CISA 26 Jun 2025
CVE-2023-36934

In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4...

High Not in CISA 27 Jun 2025
CVE-2017-9248

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect...

Confirmed In CISA 03 Nov 2021
CVE-2019-18935

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is...

Confirmed In CISA 03 Nov 2021
CVE-2017-11317

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows...

Confirmed In CISA 11 Apr 2022
CVE-2017-11357

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to...

Confirmed In CISA 26 Jan 2023
CVE-2023-34362

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL...

Confirmed In CISA 02 Jun 2023
CVE-2023-40044

WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability

Confirmed In CISA 05 Oct 2023
CVE-2024-4358

Registration Authentication Bypass Vulnerability

Confirmed In CISA 13 Jun 2024
CVE-2024-6670

WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability

Confirmed In CISA 16 Sep 2024
CVE-2024-1212

LoadMaster Pre-Authenticated OS Command Injection

Confirmed In CISA 18 Nov 2024
CVE-2024-4885

WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability

Confirmed In CISA 03 Mar 2025
CVE-2024-5806

MOVEit Transfer Authentication Bypass Vulnerability

High Not in CISA 25 Jun 2024

Common Vulnerability Classes (CWE)

  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 5
  • CWE-502 — Deserialization of Untrusted Data 2
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
  • CWE-287 — Improper Authentication 1
  • CWE-290 — Authentication Bypass by Spoofing 1
  • CWE-326 — Inadequate Encryption Strength 1
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1
  • CWE-522 — Insufficiently Protected Credentials 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology