netVigilance Vulnerability intelligence since 2004

Progress

9 Progress vulnerabilities with confirmed exploitation in the wild, as published by CISA; 9 past the federal remediation deadline. This is a static slice of the catalog — open the full catalog for search and filters.

Known exploited vulnerabilities for Progress
Vulnerability Status
overdue 31d2026-08-10 CVE-2026-8037 Progress / LoadMaster Progress LoadMaster Command Injection Vulnerability 2026-08-07 9.8 past due
overdue 535d2025-03-24 CVE-2024-4885 Progress / WhatsUp Gold Progress WhatsUp Gold Path Traversal Vulnerability 2025-03-03 9.8 past due
overdue 640d2024-12-09 CVE-2024-1212 Progress / Kemp LoadMaster Progress Kemp LoadMaster OS Command Injection Vulnerability 2024-11-18 9.8 past due
overdue 703d2024-10-07 CVE-2024-6670 Progress / WhatsUp Gold Progress WhatsUp Gold SQL Injection Vulnerability 2024-09-16 9.8 past dueransomware
overdue 798d2024-07-04 CVE-2024-4358 Progress / Telerik Report Server Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability 2024-06-13 9.8 past due
overdue 1050d2023-10-26 CVE-2023-40044 Progress / WS_FTP Server Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability 2023-10-05 8.8 past dueransomware
overdue 1175d2023-06-23 CVE-2023-34362 Progress / MOVEit Transfer Progress MOVEit Transfer SQL Injection Vulnerability 2023-06-02 9.8 past dueransomware
overdue 1591d2022-05-03 CVE-2019-18935 Progress / Telerik UI for ASP.NET AJAX Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability 2021-11-03 9.8 past dueransomware
overdue 1591d2022-05-03 CVE-2017-9248 Progress / ASP.NET AJAX and Sitefinity Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability 2021-11-03 9.8 past due