FAIL › dossier
progress
VENDOR· dossier confidence 40%
Progress Software is a public software vendor with a documented history of critical security failures across its product line, including high-profile breaches like the MOVEit Transfer ransomware incident. The company's security posture is undermined by recurring vulnerability classes—unauthenticated RCEs, SQL injections, and path traversals—that frequently require customers to take defensive actions before patches are available.
Progress Software has a poor security track record characterized by repeated critical vulnerabilities across its product portfolio, including multiple unauthenticated remote code executions, SQL injections, and path traversal flaws that often require customer-side mitigation before patches are released.
- CVE-2023-34362 MOVEit SQL injection ransomware breach
- CVE-2024-6670 WhatsUp Gold password theft via SQL injection
- CVE-2026-8037 ADC OS command injection RCE
- CVE-2026-2699 ShareFile chainable pre-auth flaws
- CVE-2024-1212 LoadMaster unauthenticated RCE
- CVE-2019-18935 Telerik UI deserialization RCE
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-11-18 | CVE-2024-1212 | high | Progress Kemp LoadMaster OS command injection allows unauthenticated remote attackers to execute arbitrary system commands. |
| 2023-10-05 | CVE-2023-40044 | critical | Progress WS_FTP Server's Ad Hoc Transfer module allows authenticated attackers to execute remote commands via deserialization of untrusted data. |
| 2023-06-02 | CVE-2023-34362 | critical | An unauthenticated SQL injection flaw in Progress MOVEit Transfer allowed attackers to alter or delete database elements, leading to a ransomware-linked breach. |
| 2024-09-16 | CVE-2024-6670 | critical | An unauthenticated SQL injection in Progress WhatsUp Gold lets attackers steal encrypted passwords when only one user is configured. |
| 2021-11-03 | CVE-2019-18935 | critical | A deserialization vulnerability in Progress Telerik UI for ASP.NET AJAX allowed for remote code execution, and is actively being exploited in ransomware attacks. |
| 2026-08-07 | CVE-2026-8037 | high | Progress LoadMaster appliances have a command injection vulnerability allowing unauthenticated attackers to execute arbitrary commands. |
| 2025-03-03 | CVE-2024-4885 | high | Progress WhatsUp Gold has a path traversal vulnerability allowing unauthenticated remote code execution, currently being exploited in the wild. |
| 2021-11-03 | CVE-2017-9248 | high | Progress Telerik UI for ASP.NET AJAX and Sitefinity suffered a cryptographic weakness allowing key disclosure, XSS, ViewState compromise, and file upload/download. |
| 2026-06-04 | CVE-2026-8037 | critical | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints |
| 2024-02-21 | CVE-2024-1212 | critical | Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. |
| 2024-06-13 | CVE-2024-4358 | high | Progress Telerik Report Server allows attackers to bypass authentication via spoofing, enabling unauthorized access to report generation features. |
| 2026-07-08 | CVE-2026-8801 | low | Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4. |
| 2026-07-08 | CVE-2026-8649 | medium | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. |
| 2026-07-23 | CVE-2026-15967 | high | CVE-2026-15967: Insufficient session expiration vulnerability in Progress MOVEit Transfer. This |
| 2026-07-23 | CVE-2026-15966 | high | CVE-2026-15966: Permissive cross-domain security policy with untrusted domains vulnerability in |
| 2026-07-23 | CVE-2026-10697 | high | CVE-2026-10697: Improper Authentication vulnerability in Progress MOVEit Transfer. This issue a |
| 2017-08-23 | CVE-2017-11357 | critical | CVE-2017-11357: Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restri |
"Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process."
"Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files."
"Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code."
- Progress Software (PRGS) Company Profile & Description · stockanalysis.com
- Progress Software Corp, PRGS:NSQ profile - FT.com · markets.ft.com
- Caterpillar Inc. - Wikipedia · en.wikipedia.org
- Progress Software Warns of "External Security Threat" to ShareFile · www.infosecurity-magazine.com
- Progress Restores ShareFile Storage Access After Security Warning · www.infosecurity-magazine.com
- CRITICAL: Progress Orders ShareFile Customers to Shut… | Innovation ND · www.innovationnetworkdesign.com
- Progress Software (PRGS) Company Profile, History, Products & Services · www.financecharts.com
- Progress Software (PRGS) Company Profile & Description · stockanalysis.com
- Secretary of State Search: Read the Results Right · proofreports.com