Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Progress Software — Vulnerabilities & Security Advisories 85

Browse all 85 CVE security advisories affecting Progress Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Progress Software develops enterprise software solutions, primarily focusing on application development platforms, database management, and integration tools for large-scale organizations. Its portfolio includes widely used technologies like OpenEdge and Telerik, which serve as critical infrastructure for business operations. Historically, security audits have identified recurring vulnerability classes within its products, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These issues often stem from input validation errors or improper access controls in legacy components. While no single catastrophic breach has defined the company’s public security history, the accumulation of 55 recorded CVEs highlights persistent challenges in maintaining secure codebases across complex, long-standing software architectures. The company generally responds to disclosures through standard patch cycles, though the volume of findings suggests ongoing efforts to modernize security practices across its diverse product line.

CVE IDTitleCVSSSeverityPublished
CVE-2026-59690 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API — LoadMasterCWE-862 8.0 High2026-07-27
CVE-2026-59689 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root — LoadMasterCWE-863 8.0 High2026-07-27
CVE-2026-59688 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality — LoadMasterCWE-78 8.4 High2026-07-27
CVE-2026-59687 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface — LoadMasterCWE-78 8.4 High2026-07-27
CVE-2026-59686 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface — LoadMasterCWE-78 8.4 High2026-07-27
CVE-2026-14932 Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart — Telerik UI for ASP.NET AJAXCWE-321 6.5 Medium2026-07-22
CVE-2026-14865 XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAXCWE-776 5.3 Medium2026-07-22
CVE-2026-13192 RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAXCWE-918 6.5 Medium2026-07-22
CVE-2026-13190 PersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAXCWE-502 8.1 High2026-07-22
CVE-2026-13189 SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAXCWE-36 7.5 High2026-07-22
CVE-2026-13188 DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAXCWE-345 5.9 Medium2026-07-22
CVE-2026-13187 DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAXCWE-470 8.1 High2026-07-22
CVE-2026-13186 AppDataStorageProvider Path Traversal Deserialization Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAXCWE-22 8.1 High2026-07-22
CVE-2026-13185 PersistenceFramework Cookie Deserialization Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAXCWE-502 8.1 High2026-07-22
CVE-2026-13184 RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAXCWE-321 7.5 High2026-07-22
CVE-2026-13183 RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAXCWE-208 7.5 High2026-07-22
CVE-2026-13182 RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAXCWE-209 7.5 High2026-07-22
CVE-2026-13181 RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAXCWE-470 8.1 High2026-07-22
CVE-2026-8079 Unintended limited set of actions with elevated privileges may be performed during PDF generation in Progress Flowmon — FlowmonCWE-863--2026-07-02
CVE-2026-9272 Possibility of unintended database operations when querying data related to detected anomalies in Progress Flowmon ADS — Flowmon ADSCWE-89--2026-07-02
CVE-2026-8037 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF — LoadMasterCWE-77 9.6 Critical2026-06-04
CVE-2026-7313 CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity — Sitefinity 8.7 High2026-06-02
CVE-2026-7312 CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity — Sitefinity 10.0 Critical2026-06-02
CVE-2026-7201 CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity — SitefinityCWE-639 8.8 High2026-06-02
CVE-2026-7198 CWE-284: Improper Access Control in web services in Progress Sitefinity — SitefinityCWE-284 9.8 Critical2026-06-02
CVE-2026-7195 CWE-20: Improper Input Validation in web services in Progress Sitefinity — SitefinityCWE-20 8.8 High2026-06-02
CVE-2026-8488 Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation — MOVEit AutomationCWE-770 4.3 Medium2026-05-20
CVE-2026-8487 Incorrect default permissions vulnerability in Progress Software MOVEit Automation — MOVEit AutomationCWE-276 6.5 Medium2026-05-20
CVE-2026-8486 Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation — MOVEit AutomationCWE-770 5.3 Medium2026-05-20
CVE-2026-8485 Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation — MOVEit AutomationCWE-789 5.9 Medium2026-05-20

This page lists every published CVE security advisory associated with Progress Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.