Progress Software Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Progress Software products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
9
In CISA KEV
5
Beyond CISA KEV
4
Sensor Observed
1
Virtual Patch Available
1
Progress Software KEVs Added by Year
9 Progress Software KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-8037
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF |
LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF | Confirmed | Not in CISA | 01 Jul 2026 |
|
CVE-2024-6671
WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability |
WhatsUp Gold | High | Not in CISA | 04 Jun 2026 |
|
CVE-2025-8868
Chef Automate compliance service SQL Injection Vulnerability |
Chef Automate | High | Not in CISA | 27 Oct 2025 |
|
CVE-2024-2389
Flowmon Unauthenticated Command Injection Vulnerability |
Flowmon | High | Not in CISA | 26 Jun 2025 |
|
CVE-2023-40044
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability |
WS_FTP Server | Confirmed | In CISA | 05 Oct 2023 |
|
CVE-2024-4358
Registration Authentication Bypass Vulnerability |
Telerik Report Server | Confirmed | In CISA | 13 Jun 2024 |
|
CVE-2024-6670
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability |
WhatsUp Gold | Confirmed | In CISA | 16 Sep 2024 |
|
CVE-2024-1212
LoadMaster Pre-Authenticated OS Command Injection |
LoadMaster | Confirmed | In CISA | 18 Nov 2024 |
|
CVE-2024-4885
WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability |
WhatsUp Gold | Confirmed | In CISA | 03 Mar 2025 |
Common Vulnerability Classes (CWE)
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 3
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
- CWE-290 — Authentication Bypass by Spoofing 1
- CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
- CWE-502 — Deserialization of Untrusted Data 1
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology