Brand
Progress: actively exploited vulnerabilities
11 vulnerabilities in Progress products (Telerik UI for ASP.NET AJAX, Kemp LoadMaster, WhatsUp Gold…) are in CISA’s catalog of exploited vulnerabilities, 1 of them added in the last 90 days. Last added: August 7, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
1 vulnerability added in the last 12 months
-
11 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one Progress category to your radar, or open its page.
- Frameworks and libraries 4 vulnerabilities
- Load balancers and access gateways (ADC) 2 vulnerabilities
- Managed file transfer (MFT) 2 vulnerabilities
- Monitoring, ITSM and asset management 2 vulnerabilities
- ERP, business applications and databases 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
Follow a single Progress product (Telerik UI for ASP.NET AJAX, Kemp LoadMaster…) rather than the whole brand.
- Telerik UI for ASP.NET AJAX4 vulnerabilities, Frameworks
- Kemp LoadMaster2 vulnerabilities, ADCs
- WhatsUp Gold2 vulnerabilities, Monitoring and ITSM
- MOVEit Transfer1 vulnerability, File transfer (MFT)
- Telerik Report Server1 vulnerability, Business apps and data
- WS_FTP Server1 vulnerability, File transfer (MFT)
Names used by CISA: Progress, Telerik. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Progress list.
- Rank 1
Progress Kemp LoadMasterCVE-2026-8037
Progress LoadMaster Command Injection Vulnerability
Hunt for compromise (CISA)
CVSS severity 9.8critical
Added Aug 7, 2026
- Rank 2
Progress WhatsUp GoldCVE-2024-4885
Progress WhatsUp Gold Path Traversal Vulnerability
CVSS severity 9.8critical
Added Mar 3, 2025
- Rank 3
Progress Kemp LoadMasterCVE-2024-1212
Progress Kemp LoadMaster OS Command Injection Vulnerability
CVSS severity 9.8critical
Added Nov 18, 2024
- Rank 4
Progress WhatsUp GoldCVE-2024-6670
Progress WhatsUp Gold SQL Injection Vulnerability
Ransomware
CVSS severity 9.8critical
Added Sep 16, 2024
- Rank 5
Progress Telerik Report ServerCVE-2024-4358
Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability
CVSS severity 9.8critical
Added Jun 13, 2024
- Rank 6
Progress MOVEit TransferCVE-2023-34362
Progress MOVEit Transfer SQL Injection Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jun 2, 2023
- Rank 7
Progress Telerik UI for ASP.NET AJAXCVE-2017-11357
Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
RansomwareCVE from 2017, added in 2023
CVSS severity 9.8critical
Added Jan 26, 2023
- Rank 8
Progress Telerik UI for ASP.NET AJAXCVE-2017-11317
Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability
CVE from 2017, added in 2022
CVSS severity 9.8critical
Added Apr 11, 2022
- Rank 9
Progress Telerik UI for ASP.NET AJAXCVE-2017-9248
Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
CVE from 2017, added in 2021
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 10
Progress Telerik UI for ASP.NET AJAXCVE-2019-18935
Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
RansomwareCVE from 2019, added in 2021
CVSS severity 9.8critical
Added Nov 3, 2021
Show 1 more vulnerability
- Rank 11
Progress WS_FTP ServerCVE-2023-40044
Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability
Ransomware
CVSS severity 8.8high
Added Oct 5, 2023
Follow and verify
Get new Progress vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.