Vendor

Progress

As of , 9 Progress vulnerabilities are on CISA's list of exploited vulnerabilities, 4 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2026-8037.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-8037Command InjectionProgress LoadMasterPatch nowForensic triage required by CISA0.77
2CVE-2024-1212OS Command InjectionProgress Kemp LoadMasterPatch this weekMetasploit module; EPSS 0.950.95
3CVE-2024-6670SQL InjectionProgress WhatsUp GoldPatch this weekRansomware use; Metasploit module; EPSS 0.930.93
4CVE-2024-4358Authentication Bypass by SpoofingProgress Telerik Report ServerPatch this weekMetasploit module; EPSS 0.970.97
5CVE-2023-40044Deserialization of Untrusted DataProgress WS_FTP ServerPatch this weekRansomware use; Metasploit module; EPSS 0.900.90
6CVE-2023-34362SQL InjectionProgress MOVEit TransferPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
7CVE-2019-18935Deserialization of Untrusted DataProgress Telerik UI for ASP.NET AJAXPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
8CVE-2024-4885Path TraversalProgress WhatsUp GoldPatch this weekEPSS 0.990.99
9CVE-2017-9248Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic WeaknessProgress ASP.NET AJAX and SitefinityPatch this weekEPSS 0.750.75

Products

  • WhatsUp Gold2 entries
  • ASP.NET AJAX and Sitefinity1 entry
  • Kemp LoadMaster1 entry
  • LoadMaster1 entry
  • MOVEit Transfer1 entry
  • Telerik Report Server1 entry
  • Telerik UI for ASP.NET AJAX1 entry
  • WS_FTP Server1 entry

Added each year

1232021: 2220212022: nonenone20222023: 2220232024: 3320242025: 1120252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20212
2022none
20232
20243
20251
20261

Used in ransomware