Skip to content
COOEY

FAIL › dossier

progress

VENDOR

· dossier confidence 40%

Progress Software is a public software vendor with a documented history of critical security failures across its product line, including high-profile breaches like the MOVEit Transfer ransomware incident. The company's security posture is undermined by recurring vulnerability classes—unauthenticated RCEs, SQL injections, and path traversals—that frequently require customers to take defensive actions before patches are available.

PROFILE
Categorysoftware vendorWhat they doProgress Software Corporation develops, deploys, and manages AI-powered applications and digital experiences, including enterprise file-sharing services like ShareFile and MFT automation tools.Ownershippublic Websitehttps://www.progress.com ↗
SECURITY POSTURE

Progress Software has a poor security track record characterized by repeated critical vulnerabilities across its product portfolio, including multiple unauthenticated remote code executions, SQL injections, and path traversal flaws that often require customer-side mitigation before patches are released.

Notable failures
  • CVE-2023-34362 MOVEit SQL injection ransomware breach
  • CVE-2024-6670 WhatsUp Gold password theft via SQL injection
  • CVE-2026-8037 ADC OS command injection RCE
  • CVE-2026-2699 ShareFile chainable pre-auth flaws
  • CVE-2024-1212 LoadMaster unauthenticated RCE
  • CVE-2019-18935 Telerik UI deserialization RCE
Patterns: repeated unauthenticated remote code execution via OS command injection; SQL injection flaws enabling data exfiltration and ransomware attacks; path traversal vulnerabilities allowing unauthorized file access and RCE; deserialization of untrusted data leading to server-side code execution
FAILURE HISTORY · 17
DATEEVENTSEVSUMMARY
2024-11-18 CVE-2024-1212 high Progress Kemp LoadMaster OS command injection allows unauthenticated remote attackers to execute arbitrary system commands.
2023-10-05 CVE-2023-40044 critical Progress WS_FTP Server's Ad Hoc Transfer module allows authenticated attackers to execute remote commands via deserialization of untrusted data.
2023-06-02 CVE-2023-34362 critical An unauthenticated SQL injection flaw in Progress MOVEit Transfer allowed attackers to alter or delete database elements, leading to a ransomware-linked breach.
2024-09-16 CVE-2024-6670 critical An unauthenticated SQL injection in Progress WhatsUp Gold lets attackers steal encrypted passwords when only one user is configured.
2021-11-03 CVE-2019-18935 critical A deserialization vulnerability in Progress Telerik UI for ASP.NET AJAX allowed for remote code execution, and is actively being exploited in ransomware attacks.
2026-08-07 CVE-2026-8037 high Progress LoadMaster appliances have a command injection vulnerability allowing unauthenticated attackers to execute arbitrary commands.
2025-03-03 CVE-2024-4885 high Progress WhatsUp Gold has a path traversal vulnerability allowing unauthenticated remote code execution, currently being exploited in the wild.
2021-11-03 CVE-2017-9248 high Progress Telerik UI for ASP.NET AJAX and Sitefinity suffered a cryptographic weakness allowing key disclosure, XSS, ViewState compromise, and file upload/download.
2026-06-04 CVE-2026-8037 critical OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
2024-02-21 CVE-2024-1212 critical Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
2024-06-13 CVE-2024-4358 high Progress Telerik Report Server allows attackers to bypass authentication via spoofing, enabling unauthorized access to report generation features.
2026-07-08 CVE-2026-8801 low Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
2026-07-08 CVE-2026-8649 medium Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
2026-07-23 CVE-2026-15967 high CVE-2026-15967: Insufficient session expiration vulnerability in Progress MOVEit Transfer. This
2026-07-23 CVE-2026-15966 high CVE-2026-15966: Permissive cross-domain security policy with untrusted domains vulnerability in
2026-07-23 CVE-2026-10697 high CVE-2026-10697: Improper Authentication vulnerability in Progress MOVEit Transfer. This issue a
2017-08-23 CVE-2017-11357 critical CVE-2017-11357: Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restri
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Progress faced severe fallout for a critical deserialization vulnerability allowing remote code execution, though the NVD entry itself is neutral and factual.
synthesissevere-fallout-0.60
Progress faced severe fallout due to a critical cryptographic weakness in its UI components, allowing key disclosure, XSS, and file manipulation, though the NVD entry itself is neutral in tone, the na
synthesissevere-fallout-0.60
CVE-2017-11357 allowed arbitrary code execution via unvalidated file uploads in Progress Telerik UI for ASP.NET AJAX, a critical flaw with severe fallout for affected organizations and the vendor's re
cooey ↗severe-fallout+0.00
neutral
"Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process."
cooey ↗severe-fallout+0.00
neutral
"Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files."
cooey ↗severe-fallout-0.60
NVD entry confirms critical vulnerability allowing arbitrary code execution via unvalidated file uploads in Progress Telerik UI for ASP.NET AJAX, indicating severe fallout for the vendor.
"Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code."
Open questions: Exact founding year and headquarters location not explicitly stated in provided web evidence · Current employee count not available in provided web evidence
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-18 04:15:30.068018+00:00