CVE-2026-16137Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller Exploitation status Not known exploited Fix YesAffected product S ShareFile Storage Zones Controller Published 08/17/2026 Severity High CVE-2026-16138Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO service Exploitation status Not known exploited Fix YesAffected product S ShareFile Storage Zones Controller Published 08/17/2026 Severity High CVE-2026-16139Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution Exploitation status Not known exploited Fix YesAffected product S ShareFile Storage Zones Controller Published 08/17/2026 Severity High CVE-2026-65941WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service. Exploitation status Not known exploited Fix YesAffected product W WhatsUp Gold Published 08/12/2026 Severity High CVE-2026-65940WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on the host server. Exploitation status Not known exploited Fix YesAffected product W WhatsUp Gold Published 08/12/2026 Severity Medium CVE-2026-65939WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler. Exploitation status Not known exploited Fix YesAffected product W WhatsUp Gold Published 08/12/2026 Severity Medium CVE-2026-65938WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API. Exploitation status Not known exploited Fix YesAffected product W WhatsUp Gold Published 08/12/2026 Severity Medium CVE-2026-65937WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UI Exploitation status Not known exploited Fix YesAffected product W WhatsUp Gold Published 08/12/2026 Severity High CVE-2026-9203Server-side request forgery in Progress MarkLogic Server Exploitation status Not known exploited Fix YesAffected product M MarkLogic Server Published 08/05/2026 Severity High CVE-2026-9195Cross-site scripting in Progress MarkLogic Server Query Console Exploitation status Not known exploited Fix YesAffected product M MarkLogic Server Published 08/05/2026 Severity Critical CVE-2026-9193Privilege escalation in Progress MarkLogic Server Hadoop integration Exploitation status Not known exploited Fix YesAffected product M MarkLogic Server Published 08/05/2026 Severity Critical CVE-2026-9192Authentication bypass in Progress MarkLogic Server ODBC App Server Exploitation status Not known exploited Fix YesAffected product M MarkLogic Server Published 08/05/2026 Severity Critical CVE-2026-9190HTTP request smuggling in Progress MarkLogic Server Exploitation status Not known exploited Fix YesAffected product M MarkLogic Server Published 08/05/2026 Severity Critical CVE-2026-8709Privilege escalation in Progress MarkLogic Server REST document patch operation Exploitation status Not known exploited Fix YesAffected product M MarkLogic Server Published 08/05/2026 Severity Critical CVE-2026-7557SAML authentication bypass in Progress MarkLogic Server Exploitation status Not known exploited Fix YesAffected product M MarkLogic Server Published 08/05/2026 Severity Critical CVE-2026-7329Privilege escalation in Progress MarkLogic Server REST query interfaces Exploitation status Not known exploited Fix YesAffected product M MarkLogic Server Published 08/05/2026 Severity Critical CVE-2026-7327Privilege escalation in Progress MarkLogic Server REST API document processing Exploitation status Not known exploited Fix YesAffected product M MarkLogic Server Published 08/05/2026 Severity High CVE-2026-7326Cross-site request forgery in Progress MarkLogic Server Admin UI Exploitation status Not known exploited Fix YesAffected product M MarkLogic Server Published 08/05/2026 Severity High CVE-2026-59690Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 07/27/2026 Severity High CVE-2026-59689Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 07/27/2026 Severity High CVE-2026-59688Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 07/27/2026 Severity High CVE-2026-59687Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 07/27/2026 Severity High CVE-2026-59686Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 07/27/2026 Severity High CVE-2026-15968Stored XSS vulnerability in MOVEit Transfer Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 07/23/2026 Severity High CVE-2026-15967MOVEit Transfer refresh-token processing does not enforce updated account restrictions Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 07/23/2026 Severity High CVE-2026-15966Improper CORS handling in MOVEit Transfer Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 07/23/2026 Severity High CVE-2026-10697MFA Bypass in MOVEit Transfer Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 07/23/2026 Severity High CVE-2026-14932Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity Medium CVE-2026-14865XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity Medium CVE-2026-13192RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity Medium CVE-2026-13190PersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13189SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13188DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity Medium CVE-2026-13187DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13186AppDataStorageProvider Path Traversal Deserialization Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13185PersistenceFramework Cookie Deserialization Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13184RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13183RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13182RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13181RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-15724Path traversal in Progress ShareFile Storage Zones Controller (SZC) Exploitation status Not known exploited Fix YesAffected product S ShareFile Storage Zones Controller Published 07/21/2026 Severity High CVE-2026-8801File Extension Restriction Bypass in MOVEit Transfer Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 07/08/2026 Severity Low CVE-2026-8800Cross-Org External Token Metadata accessible to AuditUser role Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 07/08/2026 Severity Low CVE-2026-8651IPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit Transfer Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 07/08/2026 Severity Low CVE-2026-8650Authenticated Path Traversal allows MOVEit admins to view arbitrary system files Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 07/08/2026 Severity Medium CVE-2026-8649Institution scope bypass vulnerability in custom reports Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 07/08/2026 Severity Medium CVE-2026-11903Stored XSS in MOVEit Transfer Ad Hoc module Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 07/08/2026 Severity High CVE-2026-10699Memory leak in SFTP service can result in a denial of service in MOVEit Transfer Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 07/08/2026 Severity High CVE-2026-10698Table scope bypass vulnerability in custom reports Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 07/08/2026 Severity High CVE-2026-8079Unintended limited set of actions with elevated privileges may be performed during PDF generation in Progress Flowmon Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon Published 07/02/2026 Severity High CVE-2026-9272Possibility of unintended database operations when querying data related to detected anomalies in Progress Flowmon ADS Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon ADS Published 07/02/2026 Severity High CVE-2026-8037OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF Exploitation status KEV Fix YesAffected product L LoadMaster Published 06/04/2026 Severity Critical CVE-2026-7313CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity Exploitation status Not known exploited Fix YesAffected product S Sitefinity Published 06/02/2026 Severity High CVE-2026-7312CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity Exploitation status Not known exploited Fix YesAffected product S Sitefinity Published 06/02/2026 Severity Critical CVE-2026-7201CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity Exploitation status Not known exploited Fix YesAffected product S Sitefinity Published 06/02/2026 Severity High CVE-2026-7198CWE-284: Improper Access Control in web services in Progress Sitefinity Exploitation status Not known exploited Fix YesAffected product S Sitefinity Published 06/02/2026 Severity Critical CVE-2026-7195CWE-20: Improper Input Validation in web services in Progress Sitefinity Exploitation status Not known exploited Fix YesAffected product S Sitefinity Published 06/02/2026 Severity High CVE-2026-8488Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation Exploitation status Not known exploited Fix YesAffected product M MOVEit Automation Published 05/20/2026 Severity Medium CVE-2026-8487Incorrect default permissions vulnerability in Progress Software MOVEit Automation Exploitation status Not known exploited Fix YesAffected product M MOVEit Automation Published 05/20/2026 Severity Medium CVE-2026-8486Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation Exploitation status Not known exploited Fix YesAffected product M MOVEit Automation Published 05/20/2026 Severity Medium CVE-2026-8485Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation Exploitation status Not known exploited Fix YesAffected product M MOVEit Automation Published 05/20/2026 Severity Medium CVE-2026-5174Improper Access Control Vulnerability in Progress MOVEit Automation Exploitation status Not known exploited Fix YesAffected product M MOVEit Automation Published 04/30/2026 Severity High CVE-2026-4670Improper Authentication vulnerability in Progress MOVEit Automation Exploitation status Not known exploited Fix YesAffected product M MOVEit Automation Published 04/30/2026 Severity Critical CVE-2026-6023Deserialization of Untrusted Data Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 04/22/2026 Severity High CVE-2026-6022Uncontrolled Resource Consumption Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 04/22/2026 Severity High CVE-2026-4048OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 04/20/2026 Severity High CVE-2026-3519OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 04/20/2026 Severity High CVE-2026-3518OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 04/20/2026 Severity High CVE-2026-3517OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 04/20/2026 Severity High CVE-2026-2737Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon web application Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon Published 04/02/2026 Severity High CVE-2026-3692Unintended command execution during report generation in Progress Flowmon Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon Published 04/02/2026 Severity High CVE-2026-2701RCE vulnerability in Progress ShareFile Storage Zones Controller (SZC) Exploitation status Not known exploited Fix YesAffected product S ShareFile Storage Zones Controller Published 04/02/2026 Severity Critical CVE-2026-2699EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC) Exploitation status Public exploit Fix YesAffected product S ShareFile Storage Zones Controller Published 04/02/2026 Severity Critical CVE-2026-2514Possibility of unintended actions when viewing maliciously crafted network data in Progress Flowmon ADS web application Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon ADS Published 03/12/2026 Severity High CVE-2026-2513Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon ADS web application Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon ADS Published 03/12/2026 Severity High CVE-2026-2878Insufficient Entropy Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 02/25/2026 Severity Medium CVE-2025-13447OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 01/13/2026 Severity High CVE-2025-13444OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 01/13/2026 Severity High CVE-2025-13774SQL injection leading to privilege escalation in Progress Flowmon ADS Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon ADS Published 01/13/2026 Severity High CVE-2025-11235MOVEit Transfer REST API does not require current password in order to initiate the password change process Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 01/06/2026 Severity Low CVE-2025-13147External Service Interaction (DNS) Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 11/19/2025 Severity Medium CVE-2025-10703Exploitation status Not known exploited Fix YesAffected product D DataDirect Connect for JDBC for Amazon Redshift Published 11/19/2025 Severity High CVE-2025-10702Exploitation status Not known exploited Fix YesAffected product D DataDirect Connect for JDBC for Amazon Redshift Published 11/19/2025 Severity High CVE-2025-10932AS2 module allows uncontrolled file uploads Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 10/29/2025 Severity High CVE-2025-6505Exploitation status Not known exploited Fix YesAffected product H Hybrid Data Pipeline Published 07/29/2025 Severity High CVE-2025-6504Possibilities of IP Spoofing via X-Forwarded-For (XFF) Header Exploitation status Not known exploited Fix YesAffected product H Hybrid Data Pipeline Published 07/29/2025 Severity High CVE-2025-3600Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 05/14/2025 Severity High CVE-2025-2572WhatsUp Gold NmConfigurationManager.exe database manipulation vulnerability Exploitation status Not known exploited Fix Not confirmed Affected product W WhatsUp Gold Published 04/14/2025 Severity Medium CVE-2025-1758Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 03/19/2025 Severity Medium CVE-2025-2324A MOVEit Transfer user configured as a Shared Account can gain unintended List permissions on a folder Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 03/19/2025 Severity Medium CVE-2024-6097Absolute Path Traversal Vulnerability Exploitation status Not known exploited Fix YesAffected product P Progress® Telerik® Reporting Published 02/12/2025 Severity Medium CVE-2024-11629Telerik Document Processing RTF Export of Arbitrary File Path Exploitation status Not known exploited Fix YesAffected product P Progress® Telerik® Document Processing Libraries Published 02/12/2025 Severity High CVE-2024-11628Prototype Pollution in Progress® Telerik® Kendo UI for Vue Exploitation status Not known exploited Fix YesAffected product P Progress® Telerik® Kendo UI for Vue Published 02/12/2025 Severity Medium CVE-2024-11343Telerik Document Processing Path Traversal Exploitation status Not known exploited Fix YesAffected product T Telerik Document Processing Libraries Published 02/12/2025 Severity High CVE-2024-12629Prototype Pollution in Progress® Telerik® KendoReact Exploitation status Not known exploited Fix YesAffected product T Telerik KendoReact Published 02/12/2025 Severity Medium CVE-2025-0332Progress UI for WinForms decompression path traversal vulnerability Exploitation status Not known exploited Fix YesAffected product P Progress® Telerik® UI for WinForms Published 02/12/2025 Severity High CVE-2025-0556Telerik Report Server Clear Text Transmission of Agent Commands Exploitation status Not known exploited Fix YesAffected product T Telerik Report Server Published 02/12/2025 Severity High CVE-2024-12251Improper neutralization special element in hyperlinks Exploitation status Not known exploited Fix YesAffected product T Telerik UI for WinUI Published 02/12/2025 Severity High CVE-2024-56135Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 02/05/2025 Severity High CVE-2024-56134Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 02/05/2025 Severity High