VulnSea

progress has 13 CVEs on record between 2017 and 2026. Disclosures have slowed: 0 in the last 90 days after 7 in the 90 before. The busiest recent month was May 2026 with 4. The median CVSS is 6.5 (medium), with 3 rated critical. 23% have been exploited in the wild — well above the 1% corpus average, so progress flaws are worth patching on sight. The median gap from publication to a KEV listing is 271 days (3 cases). The dominant weakness classes are CWE-78 (3) and CWE-79 (3). Most affected products: moveit_automation (4), connection_manager_for_objectscale (2), flowmon (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
23% vs 1% corpus
Median CVSS
6.5
Publish → KEV
271 d median(3)
Last 90 days
0 prev 7

Products

  • moveit_automation 4
  • connection_manager_for_objectscale 2
  • flowmon 2
  • flowmon_anomaly_detection_system 2
  • loadmaster 2
  • telerik_ui_for_asp.net_ajax 1
13
Total CVEs
3
Critical
3
CISA KEV
3
Exploited

progress vulnerabilities

CVEs affecting progress, newest first. Open any entry for full detail, references, and exploit status.

13 CVEsRSS

CVE-2026-8037Critical· 9.6CISA KEVPoC
3mo ago

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…

Hadalprogress · connection_manager_for_objectscaleEPSS 100%via NVD
CVE-2026-8488Medium· 4.3
4mo ago

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Sunlitprogress · moveit_automationEPSS 0.36%via NVD
CVE-2026-8487Medium· 6.5
4mo ago

Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Sunlitprogress · moveit_automationEPSS 0.28%via NVD
CVE-2026-8486Medium· 5.3
4mo ago

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Sunlitprogress · moveit_automationEPSS 0.40%via NVD
CVE-2026-8485Medium· 5.9
4mo ago

Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Sunlitprogress · moveit_automationEPSS 0.35%via NVD
CVE-2026-3692High· 8.8
5mo ago

In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.

In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.

Twilightprogress · flowmonEPSS 0.42%via NVD
CVE-2026-2737Medium· 6.1
5mo ago

A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web sess…

A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web sess…

Sunlitprogress · flowmonEPSS 0.20%via NVD
CVE-2026-2514Medium· 6.1
6mo ago

In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authen…

In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authen…

Sunlitprogress · flowmon_anomaly_detection_systemEPSS 0.18%via NVD
CVE-2026-2513Medium· 6.1
6mo ago

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web …

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web …

Sunlitprogress · flowmon_anomaly_detection_systemEPSS 0.16%via NVD
CVE-2025-13444High· 8.4
8mo ago

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsani…

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsani…

Twilightprogress · connection_manager_for_objectscaleEPSS 27%via NVD
CVE-2024-1212Critical· 10.0CISA KEVPoC
2y ago

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Hadalprogress · loadmasterEPSS 95%via NVD
CVE-2014-5287High· 8.8PoC
6y ago

A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).

A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).

Midnightprogress · loadmasterEPSS 8.0%via NVD
CVE-2017-11357Critical· 9.8CISA KEVPoC
9y ago

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

Hadalprogress · telerik_ui_for_asp.net_ajaxEPSS 78%via NVD
progress vulnerabilities (CVEs) · VulnSea