Browse all 90 CVE security advisories affecting Progress Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Progress Software develops enterprise software solutions, primarily focusing on application development platforms, database management, and integration tools for large-scale organizations. Its portfolio includes widely used technologies like OpenEdge and Telerik, which serve as critical infrastructure for business operations. Historically, security audits have identified recurring vulnerability classes within its products, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These issues often stem from input validation errors or improper access controls in legacy components. While no single catastrophic breach has defined the company’s public security history, the accumulation of 55 recorded CVEs highlights persistent challenges in maintaining secure codebases across complex, long-standing software architectures. The company generally responds to disclosures through standard patch cycles, though the volume of findings suggests ongoing efforts to modernize security practices across its diverse product line.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-8488 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation — MOVEit Automation CWE-770 | 4.3 | Medium | 2026-05-20 |
| CVE-2026-8487 | Incorrect default permissions vulnerability in Progress Software MOVEit Automation — MOVEit Automation CWE-276 | 6.5 | Medium | 2026-05-20 |
| CVE-2026-8486 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation — MOVEit Automation CWE-770 | 5.3 | Medium | 2026-05-20 |
| CVE-2026-8485 | Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation — MOVEit Automation CWE-789 | 5.9 | Medium | 2026-05-20 |
| CVE-2026-5174 | Improper Access Control Vulnerability in Progress MOVEit Automation — MOVEit Automation CWE-20 | 7.7 | High | 2026-04-30 |
| CVE-2026-4670 | Improper Authentication vulnerability in Progress MOVEit Automation — MOVEit Automation CWE-305 | 9.8 | Critical | 2026-04-30 |
This page lists every published CVE security advisory associated with Progress Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.