CyberMax
Home › Exploited CVEs

Progress known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 9 Progress CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2026-08-07), and 4 are known to be used in ransomware campaigns.

Progress CVEs added to CISA KEV per year
2021: 2202122023: 2202322024: 3202432025: 1202512026: 120261

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Progress products

WhatsUp Gold (2), LoadMaster (1), Kemp LoadMaster (1), Telerik Report Server (1), WS_FTP Server (1), MOVEit Transfer (1), Telerik UI for ASP.NET AJAX (1), ASP.NET AJAX and Sitefinity (1).

All Progress CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-8037LoadMasterLoadMaster Command Injection2026-08-072026-08-1077.4%–
CVE-2024-4885WhatsUp GoldWhatsUp Gold Path Traversal2025-03-032025-03-2499.3%–
CVE-2024-1212Kemp LoadMasterKemp LoadMaster OS Command Injection2024-11-182024-12-0995.4%–
CVE-2024-6670WhatsUp GoldWhatsUp Gold SQL Injection2024-09-162024-10-0793.0%Yes
CVE-2024-4358Telerik Report ServerTelerik Report Server Authentication Bypass by Spoofing2024-06-132024-07-0497.5%–
CVE-2023-40044WS_FTP ServerWS_FTP Server Deserialization of Untrusted Data2023-10-052023-10-2690.1%Yes
CVE-2023-34362MOVEit TransferMOVEit Transfer SQL Injection2023-06-022023-06-2399.9%Yes
CVE-2019-18935Telerik UI for ASP.NET AJAXTelerik UI for ASP.NET AJAX Deserialization of Untrusted Data2021-11-032022-05-0399.7%Yes
CVE-2017-9248ASP.NET AJAX and SitefinityTelerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness2021-11-032022-05-0375.1%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors