Vendor
Progress
As of , 9 Progress vulnerabilities are on CISA's list of exploited vulnerabilities, 4 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2026-8037.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-8037Command Injection | Progress LoadMaster | Patch nowForensic triage required by CISA | 0.77 | ||
| 2 | CVE-2024-1212OS Command Injection | Progress Kemp LoadMaster | Patch this weekMetasploit module; EPSS 0.95 | 0.95 | ||
| 3 | CVE-2024-6670SQL Injection | Progress WhatsUp Gold | Patch this weekRansomware use; Metasploit module; EPSS 0.93 | 0.93 | ||
| 4 | CVE-2024-4358Authentication Bypass by Spoofing | Progress Telerik Report Server | Patch this weekMetasploit module; EPSS 0.97 | 0.97 | ||
| 5 | CVE-2023-40044Deserialization of Untrusted Data | Progress WS_FTP Server | Patch this weekRansomware use; Metasploit module; EPSS 0.90 | 0.90 | ||
| 6 | CVE-2023-34362SQL Injection | Progress MOVEit Transfer | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 7 | CVE-2019-18935Deserialization of Untrusted Data | Progress Telerik UI for ASP.NET AJAX | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 8 | CVE-2024-4885Path Traversal | Progress WhatsUp Gold | Patch this weekEPSS 0.99 | 0.99 | ||
| 9 | CVE-2017-9248Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness | Progress ASP.NET AJAX and Sitefinity | Patch this weekEPSS 0.75 | 0.75 |
Products
- WhatsUp Gold2 entries
- ASP.NET AJAX and Sitefinity1 entry
- Kemp LoadMaster1 entry
- LoadMaster1 entry
- MOVEit Transfer1 entry
- Telerik Report Server1 entry
- Telerik UI for ASP.NET AJAX1 entry
- WS_FTP Server1 entry
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2021 | 2 |
| 2022 | none |
| 2023 | 2 |
| 2024 | 3 |
| 2025 | 1 |
| 2026 | 1 |