Brand
Progress: actively exploited vulnerabilities
11 vulnerabilities in Progress products (Telerik UI for ASP.NET AJAX, Kemp LoadMaster, WhatsUp Gold…) are in CISA’s catalog of exploited vulnerabilities, 1 of them added in the last 90 days. Last added: August 7, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
1 vulnerability added in the last 12 months
-
11 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one Progress category to your radar, or open its page.
- Frameworks and libraries 4 vulnerabilities
- Load balancers and access gateways (ADC) 2 vulnerabilities
- Managed file transfer (MFT) 2 vulnerabilities
- Monitoring, ITSM and asset management 2 vulnerabilities
- ERP, business applications and databases 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- Telerik UI for ASP.NET AJAX 4 vulnerabilities · Frameworks
- Kemp LoadMaster 2 vulnerabilities · ADCs
- WhatsUp Gold 2 vulnerabilities · Monitoring and ITSM
- MOVEit Transfer 1 vulnerability · File transfer (MFT)
- Telerik Report Server 1 vulnerability · Business apps and data
- WS_FTP Server 1 vulnerability · File transfer (MFT)
Names used by CISA: Progress, Telerik. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Progress list.
Rank 1Progress Kemp LoadMaster
CVE-2026-8037Hunt for compromise (CISA)
Progress LoadMaster Command Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 7, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 2Progress WhatsUp Gold
CVE-2024-4885Progress WhatsUp Gold Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 3Progress Kemp LoadMaster
CVE-2024-1212Progress Kemp LoadMaster OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 18, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 4Progress WhatsUp Gold
CVE-2024-6670Ransomware
Progress WhatsUp Gold SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 16, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 5Progress Telerik Report Server
CVE-2024-4358Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 13, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 6Progress MOVEit Transfer
CVE-2023-34362Ransomware
Progress MOVEit Transfer SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 2, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 7Progress Telerik UI for ASP.NET AJAX
CVE-2017-11357RansomwareCVE from 2017, added in 2023
Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 26, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 8Progress Telerik UI for ASP.NET AJAX
CVE-2017-11317CVE from 2017, added in 2022
Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 11, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 9Progress Telerik UI for ASP.NET AJAX
CVE-2017-9248CVE from 2017, added in 2021
Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 10Progress Telerik UI for ASP.NET AJAX
CVE-2019-18935RansomwareCVE from 2019, added in 2021
Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Show 1 more vulnerability
Rank 11Progress WS_FTP Server
CVE-2023-40044Ransomware
Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 5, 2023
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Follow and verify
Get new Progress vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.