CVE-2026-19219DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 09/02/2026 Severity High CVE-2026-18672RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 09/02/2026 Severity High CVE-2026-59690Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 07/27/2026 Severity High CVE-2026-59689Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 07/27/2026 Severity High CVE-2026-59688Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 07/27/2026 Severity High CVE-2026-59687Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 07/27/2026 Severity High CVE-2026-59686Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 07/27/2026 Severity High CVE-2026-14932Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity Medium CVE-2026-14865XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity Medium CVE-2026-13192RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity Medium CVE-2026-13190PersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13189SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13188DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity Medium CVE-2026-13187DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13186AppDataStorageProvider Path Traversal Deserialization Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13185PersistenceFramework Cookie Deserialization Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13184RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13183RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13182RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-13181RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 07/22/2026 Severity High CVE-2026-8079Unintended limited set of actions with elevated privileges may be performed during PDF generation in Progress Flowmon Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon Published 07/02/2026 Severity High CVE-2026-9272Possibility of unintended database operations when querying data related to detected anomalies in Progress Flowmon ADS Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon ADS Published 07/02/2026 Severity High CVE-2026-8037OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF Exploitation status KEV Fix YesAffected product L LoadMaster Published 06/04/2026 Severity Critical CVE-2026-7313CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity Exploitation status Not known exploited Fix YesAffected product S Sitefinity Published 06/02/2026 Severity High CVE-2026-7312CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity Exploitation status Not known exploited Fix YesAffected product S Sitefinity Published 06/02/2026 Severity Critical CVE-2026-7201CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity Exploitation status Not known exploited Fix YesAffected product S Sitefinity Published 06/02/2026 Severity High CVE-2026-7198CWE-284: Improper Access Control in web services in Progress Sitefinity Exploitation status Not known exploited Fix YesAffected product S Sitefinity Published 06/02/2026 Severity Critical CVE-2026-7195CWE-20: Improper Input Validation in web services in Progress Sitefinity Exploitation status Not known exploited Fix YesAffected product S Sitefinity Published 06/02/2026 Severity High CVE-2026-8488Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation Exploitation status Not known exploited Fix YesAffected product M MOVEit Automation Published 05/20/2026 Severity Medium CVE-2026-8487Incorrect default permissions vulnerability in Progress Software MOVEit Automation Exploitation status Not known exploited Fix YesAffected product M MOVEit Automation Published 05/20/2026 Severity Medium CVE-2026-8486Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation Exploitation status Not known exploited Fix YesAffected product M MOVEit Automation Published 05/20/2026 Severity Medium CVE-2026-8485Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation Exploitation status Not known exploited Fix YesAffected product M MOVEit Automation Published 05/20/2026 Severity Medium CVE-2026-5174Improper Access Control Vulnerability in Progress MOVEit Automation Exploitation status Not known exploited Fix YesAffected product M MOVEit Automation Published 04/30/2026 Severity High CVE-2026-4670Improper Authentication vulnerability in Progress MOVEit Automation Exploitation status Not known exploited Fix YesAffected product M MOVEit Automation Published 04/30/2026 Severity Critical CVE-2026-6023Deserialization of Untrusted Data Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 04/22/2026 Severity High CVE-2026-6022Uncontrolled Resource Consumption Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 04/22/2026 Severity High CVE-2026-4048OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 04/20/2026 Severity High CVE-2026-3519OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 04/20/2026 Severity High CVE-2026-3518OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 04/20/2026 Severity High CVE-2026-3517OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 04/20/2026 Severity High CVE-2026-2737Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon web application Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon Published 04/02/2026 Severity High CVE-2026-3692Unintended command execution during report generation in Progress Flowmon Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon Published 04/02/2026 Severity High CVE-2026-2514Possibility of unintended actions when viewing maliciously crafted network data in Progress Flowmon ADS web application Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon ADS Published 03/12/2026 Severity High CVE-2026-2513Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon ADS web application Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon ADS Published 03/12/2026 Severity High CVE-2026-2878Insufficient Entropy Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 02/25/2026 Severity Medium CVE-2025-6723Untrusted user data can lead to privilege escalation Exploitation status Not known exploited Fix Not confirmed Affected product C Chef Inspec Published 01/30/2026 Severity Medium CVE-2025-13447OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 01/13/2026 Severity High CVE-2025-13444OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 01/13/2026 Severity High CVE-2025-13774SQL injection leading to privilege escalation in Progress Flowmon ADS Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon ADS Published 01/13/2026 Severity High CVE-2025-11906Privilege escalation via writable configuration files in Progress Flowmon Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon Published 10/30/2025 Severity Medium CVE-2025-10240Possibility of unintended actions when a user clicks a malicious link in the Progress Flowmon web application Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon Published 10/09/2025 Severity High CVE-2025-10239Unintended command execution via troubleshooting scripts in Progress Flowmon Exploitation status Not known exploited Fix Not confirmed Affected product F Flowmon Published 10/09/2025 Severity High CVE-2025-8868Chef Automate compliance service SQL Injection Vulnerability Exploitation status Not known exploited Fix YesAffected product C Chef Automate Published 09/29/2025 Severity Critical CVE-2025-6724Chef Automate SQL Injection Vulnerability Exploitation status Not known exploited Fix YesAffected product C Chef Automate Published 09/29/2025 Severity High CVE-2025-6505CVE-2025-6505 Exploitation status Not known exploited Fix YesAffected product H Hybrid Data Pipeline Published 07/29/2025 Severity High CVE-2025-6504Possibilities of IP Spoofing via X-Forwarded-For (XFF) Header Exploitation status Not known exploited Fix YesAffected product H Hybrid Data Pipeline Published 07/29/2025 Severity High CVE-2025-6725Cross-Site Scripting (XSS) in PdfViewer Exploitation status Not known exploited Fix YesAffected product K Kendo UI for jQuery Published 07/02/2025 Severity Medium CVE-2025-3600Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAX Exploitation status Not known exploited Fix YesAffected product T Telerik UI for ASP.NET AJAX Published 05/14/2025 Severity High CVE-2024-11629Telerik Document Processing RTF Export of Arbitrary File Path Exploitation status Not known exploited Fix YesAffected product P Progress® Telerik® Document Processing Libraries Published 02/12/2025 Severity High CVE-2024-11628Prototype Pollution in Progress® Telerik® Kendo UI for Vue Exploitation status Not known exploited Fix YesAffected product P Progress® Telerik® Kendo UI for Vue Published 02/12/2025 Severity Medium CVE-2024-11343Telerik Document Processing Path Traversal Exploitation status Not known exploited Fix YesAffected product T Telerik Document Processing Libraries Published 02/12/2025 Severity High CVE-2024-12629Prototype Pollution in Progress® Telerik® KendoReact Exploitation status Not known exploited Fix YesAffected product T Telerik KendoReact Published 02/12/2025 Severity Medium CVE-2025-0332Progress UI for WinForms decompression path traversal vulnerability Exploitation status Not known exploited Fix YesAffected product P Progress® Telerik® UI for WinForms Published 02/12/2025 Severity High CVE-2025-0556Telerik Report Server Clear Text Transmission of Agent Commands Exploitation status Not known exploited Fix YesAffected product T Telerik Report Server Published 02/12/2025 Severity High CVE-2024-12251Improper neutralization special element in hyperlinks Exploitation status Not known exploited Fix YesAffected product T Telerik UI for WinUI Published 02/12/2025 Severity High CVE-2024-10095Progress UI for WPF format provider unsafe deserialization vulnerability Exploitation status Not known exploited Fix YesAffected product T Telerik UI for WPF Published 12/16/2024 Severity High CVE-2024-8049Telerik Document Processing Improper Handling of Memory Resources Exploitation status Not known exploited Fix YesAffected product T Telerik Document Processing Libraries Published 11/13/2024 Severity Medium CVE-2024-10012Progress UI for WPF format provider unsafe deserialization vulnerability Exploitation status Not known exploited Fix YesAffected product T Telerik UI for WPF Published 11/13/2024 Severity High CVE-2024-10013Progress UI for WinForms format provider unsafe deserialization vulnerability Exploitation status Not known exploited Fix YesAffected product T Telerik UI for WinForms Published 11/13/2024 Severity High CVE-2024-8015Telerik Report Server Insecure Type Resolution Exploitation status Not known exploited Fix YesAffected product T Telerik Reporting Published 10/09/2024 Severity Critical CVE-2024-7840Improper neutralization special element in hyperlinks Exploitation status Not known exploited Fix YesAffected product T Telerik Reporting Published 10/09/2024 Severity High CVE-2024-8048Telerik Reporting Insecure Expression Evaluation Exploitation status Not known exploited Fix YesAffected product T Telerik Reporting Published 10/09/2024 Severity High CVE-2024-8014Telerik Reporting EntityDataSource Insecure Type Resolution Exploitation status Not known exploited Fix YesAffected product T Telerik Reporting Published 10/09/2024 Severity High CVE-2024-8316Progress UI for WPF format provider unsafe deserialization vulnerability Exploitation status Not known exploited Fix YesAffected product T Telerik UI for WPF Published 09/25/2024 Severity High CVE-2024-7576Progress UI for WPF format provider unsafe deserialization vulnerability Exploitation status Not known exploited Fix YesAffected product T Telerik UI for WPF Published 09/25/2024 Severity High CVE-2024-7575Improper neutralization special element in hyperlinks Exploitation status Not known exploited Fix YesAffected product T Telerik UI for WPF Published 09/25/2024 Severity High CVE-2024-7679Improper neutralization special element in hyperlinks Exploitation status Not known exploited Fix YesAffected product T Telerik UI for WinForms Published 09/25/2024 Severity High CVE-2024-4837Trust Boundary Violation Vulnerability Exploitation status Not known exploited Fix YesAffected product T Telerik Report Server Published 05/15/2024 Severity Medium CVE-2024-4357XML External Entity Processing Information Disclosure Exploitation status Not known exploited Fix YesAffected product T Telerik Report Server Published 05/15/2024 Severity Medium CVE-2024-2389Flowmon Unauthenticated Command Injection Vulnerability Exploitation status Public exploit Fix YesAffected product F Flowmon Published 04/02/2024 Severity Critical CVE-2024-2449LoadMaster Cross-Site Request Forgery (CSRF) Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 03/22/2024 Severity High CVE-2024-2448LoadMaster Command Injection Vulnerability Exploitation status Not known exploited Fix YesAffected product L LoadMaster Published 03/22/2024 Severity High CVE-2024-2291MOVEit Transfer Logging Bypass Vulnerability Exploitation status Not known exploited Fix YesAffected product M MOVEit Transfer Published 03/20/2024 Severity Medium CVE-2024-1212LoadMaster Pre-Authenticated OS Command Injection Exploitation status KEV Fix YesAffected product L LoadMaster Published 02/21/2024 Severity Critical CVE-2024-0833Privilege Elevation via Telerik Test Studio Exploitation status Not known exploited Fix YesAffected product T Telerik Test Studio Published 01/31/2024 Severity High CVE-2024-0832Privilege Elevation via Telerik Reporting Installer Exploitation status Not known exploited Fix YesAffected product T Telerik Reporting Published 01/31/2024 Severity High CVE-2024-0219Privilege Elevation via Telerik JustDecompile Installer Exploitation status Not known exploited Fix YesAffected product T Telerik JustDecompile Published 01/31/2024 Severity High