Progress known exploited vulnerabilities
CISA lists 9 Progress CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2026-08-07), and 4 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2023-34362 (MOVEit Transfer): EPSS 99.9%, added 2023-06-02
- CVE-2019-18935 (Telerik UI for ASP.NET AJAX): EPSS 99.7%, added 2021-11-03
- CVE-2024-4885 (WhatsUp Gold): EPSS 99.3%, added 2025-03-03
- CVE-2024-4358 (Telerik Report Server): EPSS 97.5%, added 2024-06-13
- CVE-2024-1212 (Kemp LoadMaster): EPSS 95.4%, added 2024-11-18
Most affected Progress products
WhatsUp Gold (2), LoadMaster (1), Kemp LoadMaster (1), Telerik Report Server (1), WS_FTP Server (1), MOVEit Transfer (1), Telerik UI for ASP.NET AJAX (1), ASP.NET AJAX and Sitefinity (1).
All Progress CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-8037 | LoadMaster | LoadMaster Command Injection | 2026-08-07 | 2026-08-10 | 77.4% | – |
| CVE-2024-4885 | WhatsUp Gold | WhatsUp Gold Path Traversal | 2025-03-03 | 2025-03-24 | 99.3% | – |
| CVE-2024-1212 | Kemp LoadMaster | Kemp LoadMaster OS Command Injection | 2024-11-18 | 2024-12-09 | 95.4% | – |
| CVE-2024-6670 | WhatsUp Gold | WhatsUp Gold SQL Injection | 2024-09-16 | 2024-10-07 | 93.0% | Yes |
| CVE-2024-4358 | Telerik Report Server | Telerik Report Server Authentication Bypass by Spoofing | 2024-06-13 | 2024-07-04 | 97.5% | – |
| CVE-2023-40044 | WS_FTP Server | WS_FTP Server Deserialization of Untrusted Data | 2023-10-05 | 2023-10-26 | 90.1% | Yes |
| CVE-2023-34362 | MOVEit Transfer | MOVEit Transfer SQL Injection | 2023-06-02 | 2023-06-23 | 99.9% | Yes |
| CVE-2019-18935 | Telerik UI for ASP.NET AJAX | Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data | 2021-11-03 | 2022-05-03 | 99.7% | Yes |
| CVE-2017-9248 | ASP.NET AJAX and Sitefinity | Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness | 2021-11-03 | 2022-05-03 | 75.1% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors