Skip to content

Products › Brands

Brand

Progress: actively exploited vulnerabilities

11 vulnerabilities in Progress products (Telerik UI for ASP.NET AJAX, Kemp LoadMaster, WhatsUp Gold…) are in CISA’s catalog of exploited vulnerabilities, 1 of them added in the last 90 days. Last added: August 7, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one Progress category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

Follow a single Progress product (Telerik UI for ASP.NET AJAX, Kemp LoadMaster…) rather than the whole brand.

  • Telerik UI for ASP.NET AJAX4 vulnerabilities, Frameworks
  • Kemp LoadMaster2 vulnerabilities, ADCs
  • WhatsUp Gold2 vulnerabilities, Monitoring and ITSM
  • MOVEit Transfer1 vulnerability, File transfer (MFT)
  • Telerik Report Server1 vulnerability, Business apps and data
  • WS_FTP Server1 vulnerability, File transfer (MFT)

Names used by CISA: Progress, Telerik. Product families: indicative classification by this site.

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Progress list.

  1. Rank 1

    Progress Kemp LoadMasterCVE-2026-8037

    Progress LoadMaster Command Injection Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Aug 7, 2026

  2. Rank 2

    Progress WhatsUp GoldCVE-2024-4885

    Progress WhatsUp Gold Path Traversal Vulnerability

    CVSS severity 9.8critical

    Added Mar 3, 2025

  3. Rank 3

    Progress Kemp LoadMasterCVE-2024-1212

    Progress Kemp LoadMaster OS Command Injection Vulnerability

    CVSS severity 9.8critical

    Added Nov 18, 2024

  4. Rank 4

    Progress WhatsUp GoldCVE-2024-6670

    Progress WhatsUp Gold SQL Injection Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Sep 16, 2024

  5. Rank 5

    Progress Telerik Report ServerCVE-2024-4358

    Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability

    CVSS severity 9.8critical

    Added Jun 13, 2024

  6. Rank 6

    Progress MOVEit TransferCVE-2023-34362

    Progress MOVEit Transfer SQL Injection Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jun 2, 2023

  7. Rank 7

    Progress Telerik UI for ASP.NET AJAXCVE-2017-11357

    Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

    RansomwareCVE from 2017, added in 2023

    CVSS severity 9.8critical

    Added Jan 26, 2023

  8. Rank 8

    Progress Telerik UI for ASP.NET AJAXCVE-2017-11317

    Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability

    CVE from 2017, added in 2022

    CVSS severity 9.8critical

    Added Apr 11, 2022

  9. Rank 9

    Progress Telerik UI for ASP.NET AJAXCVE-2017-9248

    Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability

    CVE from 2017, added in 2021

    CVSS severity 9.8critical

    Added Nov 3, 2021

  10. Rank 10

    Progress Telerik UI for ASP.NET AJAXCVE-2019-18935

    Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

    RansomwareCVE from 2019, added in 2021

    CVSS severity 9.8critical

    Added Nov 3, 2021

Show 1 more vulnerability
  1. Rank 11

    Progress WS_FTP ServerCVE-2023-40044

    Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability

    Ransomware

    CVSS severity 8.8high

    Added Oct 5, 2023

Follow and verify

Get new Progress vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.