<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/marques/progress.xml</id>
  <title>Exploit Radar: exploited Progress vulnerabilities</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities for Progress products.</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/marques/progress.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/marques/progress/"/>
  <updated>2026-08-07T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-8037/</id>
    <title>CVE-2026-8037 — Progress Kemp LoadMaster</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-8037/"/>
    <updated>2026-08-07T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Progress; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on August 7, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-4885/</id>
    <title>CVE-2024-4885 — Progress WhatsUp Gold</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-4885/"/>
    <updated>2025-03-03T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Progress; if none are available, stop using the product. For cloud services, follow the guidance from Progress. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 3, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-1212/</id>
    <title>CVE-2024-1212 — Progress Kemp LoadMaster</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-1212/"/>
    <updated>2024-11-18T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Progress; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on November 18, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-6670/</id>
    <title>CVE-2024-6670 — Progress WhatsUp Gold</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-6670/"/>
    <updated>2024-09-16T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Progress; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on September 16, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-4358/</id>
    <title>CVE-2024-4358 — Progress Telerik Report Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-4358/"/>
    <updated>2024-06-13T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Progress; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on June 13, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-40044/</id>
    <title>CVE-2023-40044 — Progress WS_FTP Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-40044/"/>
    <updated>2023-10-05T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Progress; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on October 5, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-34362/</id>
    <title>CVE-2023-34362 — Progress MOVEit Transfer</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-34362/"/>
    <updated>2023-06-02T00:00:00Z</updated>
    <summary type="text">Apply the security update from Progress. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on June 2, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2017-11357/</id>
    <title>CVE-2017-11357 — Progress Telerik UI for ASP.NET AJAX</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2017-11357/"/>
    <updated>2023-01-26T00:00:00Z</updated>
    <summary type="text">Apply the security update from Progress. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on January 26, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2017-11317/</id>
    <title>CVE-2017-11317 — Progress Telerik UI for ASP.NET AJAX</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2017-11317/"/>
    <updated>2022-04-11T00:00:00Z</updated>
    <summary type="text">Apply the security update from Progress. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on April 11, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2017-9248/</id>
    <title>CVE-2017-9248 — Progress Telerik UI for ASP.NET AJAX</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2017-9248/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Progress. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-18935/</id>
    <title>CVE-2019-18935 — Progress Telerik UI for ASP.NET AJAX</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-18935/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Progress. CISA deadline: 181 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
</feed>
