Progress Software
Vulnerabilities and patches across Progress Software's edge and file-transfer product line — Kemp LoadMaster application delivery controllers, MOVEit Transfer, and other appliances whose compromise typically hands attackers a foothold at the network perimeter.
Progress WhatsUp Gold Path Traversal Vulnerability
Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.
Progress Kemp LoadMaster OS Command Injection Vulnerability
Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution.
Progress WhatsUp Gold SQL Injection Vulnerability
Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user.
Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability
Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.
Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability
Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.
Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files.
Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

Kemp LoadMaster CVE-2026-8037 Lands on CISA KEV
CISA added the critical Kemp LoadMaster command-injection flaw to its KEV catalog Friday after 792 reported exploitation attempts. If you haven't patched since June 4, that window is closed.

MOVEit Transfer and the Breach That Defined 2023
CVE-2023-34362 still scores EPSS 0.99 in July 2026, three years after Cl0p's mass-exploitation campaign. Here's what happened, what changed, and what hasn't.

Progress patches ShareFile zero-day: 5.12.5 and 6.0.2 out
Progress shipped ShareFile Storage Zone Controller 5.12.5 and 6.0.2 to fix a high-severity authenticated path traversal. CVE pending. Patch first, then bring the boxes back up.

Progress tells ShareFile on-prem users to shut down servers
Progress emailed on-prem ShareFile Storage Zone customers to shut down servers over a 'credible external threat.' No CVE, no patch — just an offline advisory.

Kemp LoadMaster Pre-Auth RCE: PoC Is Out, Patch Now
A functional proof-of-concept for a critical pre-auth RCE in Progress Kemp LoadMaster hit the internet on June 29 and eSentire started seeing exploitation attempts the same day. Progress's fix has been available since June 4.