LIVE · cybersecurity feed
Live wire
vendor1 exploited in the wild

Progress

47 CVEs published in the last four months and 2 stories. Exploited flaws first.

Critical10
High35
Medium0
Exploited (KEV)1

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-8037exploited9.6criticalconnection manager for objectscaleOS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated93d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-731210criticalsitefinityCWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.495d ago
CVE-2026-91939.9criticalmarklogic serverAn improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.631d ago
CVE-2026-73299.9criticalmarklogic serverAn improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress Mark31d ago
CVE-2026-87099.9criticalmarklogic serverAn improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Serve31d ago
CVE-2026-71989.8criticalsitefinityCWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote 95d ago
CVE-2026-91929.8criticalmarklogic serverAn authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.331d ago
CVE-2026-8037exploited9.6criticalconnection manager for objectscaleOS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated93d ago
CVE-2026-91959.3criticalmarklogic serverA cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 all31d ago
CVE-2026-75579.1criticalmarklogic serverAn improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress Mar31d ago
CVE-2026-91909.1criticalmarklogic serverAn HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.31d ago
CVE-2026-659418.8highwhatsup goldIn WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the a24d ago
CVE-2026-71958.8highsitefinityCWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.95d ago
CVE-2026-72018.8highsitefinityCWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.295d ago
CVE-2026-157248.7highsharefile storage zones controllerIn Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative46d ago
CVE-2026-73138.7highsitefinityCWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.95d ago
CVE-2026-92038.5highmarklogic serverA server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authent31d ago
CVE-2026-596878.4highconnection manager for objectscaleAn OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connec40d ago
CVE-2026-596888.4highconnection manager for objectscaleAn OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connec40d ago
CVE-2026-596868.4highconnection manager for objectscaleAn OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connec40d ago
CVE-2026-131818.1hightelerik ui for asp.net ajaxIn Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName p45d ago
CVE-2026-92728.1highflowmon anomaly detection systemIn Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is aut65d ago
CVE-2026-131868.1hightelerik ui for asp.net ajaxIn Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persisten45d ago
CVE-2026-131878.1hightelerik ui for asp.net ajaxIn Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, po45d ago
CVE-2026-131908.1hightelerik ui for asp.net ajaxIn Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utiliti45d ago
CVE-2026-131858.1hightelerik ui for asp.net ajaxIn Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceM45d ago
CVE-2026-73278.1highmarklogic serverAn improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic S31d ago
CVE-2026-659378highwhatsup goldIn WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inje24d ago
CVE-2026-596898highconnection manager for objectscaleAn Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Con40d ago
CVE-2026-161388highsharefile storage zones controllerIn Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted fil19d ago
CVE-2026-119038highmoveit transferImproper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOV59d ago
CVE-2026-596908highconnection manager for objectscaleA Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connec40d ago
CVE-2026-131837.5hightelerik ui for asp.net ajaxIn Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptog45d ago
CVE-2026-159677.5highmoveit transferInsufficient session expiration vulnerability in Progress MOVEit Transfer.44d ago
CVE-2026-131897.5hightelerik ui for asp.net ajaxIn Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the s45d ago
CVE-2026-106997.5highmoveit transferMissing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modul59d ago
CVE-2026-131827.5hightelerik ui for asp.net ajaxIn Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish dec45d ago
CVE-2026-159667.5highmoveit transferPermissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer.44d ago
CVE-2026-106977.5highmoveit transferImproper Authentication vulnerability in Progress MOVEit Transfer.44d ago
CVE-2026-131847.5hightelerik ui for asp.net ajaxIn Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and mac45d ago
CVE-2026-73267.5highmarklogic serverA cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 al31d ago
CVE-2026-80797.3highflowmonIn Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privi65d ago
CVE-2026-106987.2highmoveit transferImproper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom 59d ago
CVE-2026-161377.2highsharefile storage zones controllerIn Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform 19d ago
CVE-2026-161397.2highsharefile storage zones controllerIn Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrato19d ago
CVE-2026-159687.1highmoveit transferImproper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOV44d ago
CVE-2026-25136.1flowmon anomaly detection systemA vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who cl177d ago
CVE-2026-25146.1flowmon anomaly detection systemIn Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with acces177d ago

Filter the full tracker by Progress

Our coverage of Progress

CVE-2026-8037critical

CISA Adds Progress LoadMaster Command Injection Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Progress LoadMaster products to its Known Exploited Vulnerabilities catalog. This OS command injection flaw, tracked as CVE-2026-8037, allows unauthenticated attackers to execute arbitrary commands remotely. Exploitation attempts were observed as early as June 29, 2026, shortly after a proof-of-concept exploit became available.

CVE-2026-8037critical

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S. CISA has added a critical command injection vulnerability in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities catalog. Tracked as CVE-2026-8037, the flaw allows unauthenticated attackers to execute arbitrary code on affected devices. This addition follows reports of active exploitation attempts, with over 792 observed in the past 41 days.