<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Progress Software</title><description>Vulnerabilities and patches across Progress Software&apos;s edge and file-transfer product line — Kemp LoadMaster application delivery controllers, MOVEit Transfer, and other appliances whose compromise typically hands attackers a foothold at the network perimeter. Combined article + CVE feed for the Progress Software beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2017-9248 — Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability</title><link>https://0daynews.com/cve/cve-2017-9248/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-9248/</guid><description>Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files.</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>Progress Software</category><category>critical</category><category>cve</category></item><item><title>CVE-2019-18935 — Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2019-18935/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-18935/</guid><description>Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>Progress Software</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-40044 — Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2023-40044/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-40044/</guid><description>Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>Progress Software</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-1212 — Progress Kemp LoadMaster OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2024-1212/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-1212/</guid><description>Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution.</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>Progress Software</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-4358 — Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability</title><link>https://0daynews.com/cve/cve-2024-4358/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-4358/</guid><description>Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>Progress Software</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-4885 — Progress WhatsUp Gold Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2024-4885/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-4885/</guid><description>Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>Progress Software</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-6670 — Progress WhatsUp Gold SQL Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2024-6670/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-6670/</guid><description>Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user&apos;s encrypted password if the application is configured with only a single user.</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>Progress Software</category><category>critical</category><category>cve</category></item><item><title>Kemp LoadMaster CVE-2026-8037 Lands on CISA KEV</title><link>https://0daynews.com/articles/2026-08-08-kemp-loadmaster-cve-2026-8037-cisa-kev/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-08-kemp-loadmaster-cve-2026-8037-cisa-kev/</guid><description>CISA added the critical Kemp LoadMaster command-injection flaw to its KEV catalog Friday after 792 reported exploitation attempts. If you haven&apos;t patched since June 4, that window is closed.</description><pubDate>Sat, 08 Aug 2026 21:00:00 GMT</pubDate><category>Progress Software</category><category>article</category></item><item><title>MOVEit Transfer and the Breach That Defined 2023</title><link>https://0daynews.com/articles/2026-07-23-moveit-cve-2023-34362-three-years-clop-data-breach/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-moveit-cve-2023-34362-three-years-clop-data-breach/</guid><description>CVE-2023-34362 still scores EPSS 0.99 in July 2026, three years after Cl0p&apos;s mass-exploitation campaign. Here&apos;s what happened, what changed, and what hasn&apos;t.</description><pubDate>Thu, 23 Jul 2026 08:00:00 GMT</pubDate><category>Progress Software</category><category>article</category></item><item><title>Progress patches ShareFile zero-day: 5.12.5 and 6.0.2 out</title><link>https://0daynews.com/articles/2026-07-14-progress-sharefile-storage-zone-5-12-5-6-0-2-path-traversal-patch/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-14-progress-sharefile-storage-zone-5-12-5-6-0-2-path-traversal-patch/</guid><description>Progress shipped ShareFile Storage Zone Controller 5.12.5 and 6.0.2 to fix a high-severity authenticated path traversal. CVE pending. Patch first, then bring the boxes back up.</description><pubDate>Tue, 14 Jul 2026 17:20:00 GMT</pubDate><category>Progress Software</category><category>article</category></item><item><title>Progress tells ShareFile on-prem users to shut down servers</title><link>https://0daynews.com/articles/2026-07-10-progress-sharefile-shutdown-storage-zone-moveit-echo/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-progress-sharefile-shutdown-storage-zone-moveit-echo/</guid><description>Progress emailed on-prem ShareFile Storage Zone customers to shut down servers over a &apos;credible external threat.&apos; No CVE, no patch — just an offline advisory.</description><pubDate>Fri, 10 Jul 2026 17:15:00 GMT</pubDate><category>Progress Software</category><category>article</category></item><item><title>Kemp LoadMaster Pre-Auth RCE: PoC Is Out, Patch Now</title><link>https://0daynews.com/articles/2026-07-03-kemp-loadmaster-cve-2026-8037-pre-auth-rce/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-03-kemp-loadmaster-cve-2026-8037-pre-auth-rce/</guid><description>A functional proof-of-concept for a critical pre-auth RCE in Progress Kemp LoadMaster hit the internet on June 29 and eSentire started seeing exploitation attempts the same day. Progress&apos;s fix has been available since June 4.</description><pubDate>Fri, 03 Jul 2026 13:00:00 GMT</pubDate><category>Progress Software</category><category>article</category></item></channel></rss>