Progress security briefs
5 published alerts for Progress products and services.
Progress LoadMaster Command Injection Vulnerability
Progress LoadMaster is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-8037). Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. CISA remediation due date: 2026-08-10. If you need help checking exposure, call (864) 335-9223.
Progress WhatsUp Gold SQL Injection Vulnerability
Progress WhatsUp Gold is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-6670). Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user. CISA remediation due date: 2024-10-07. If you need help checking exposure, call (864) 335-9223.
Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability
Progress WS_FTP Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-40044). Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system. CISA remediation due date: 2023-10-26. If you need help checking exposure, call (864) 335-9223.
Progress MOVEit Transfer SQL Injection Vulnerability
Progress MOVEit Transfer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-34362). Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements. CISA remediation due date: 2023-06-23. If you need help checking exposure, call (864) 335-9223.
Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
Progress Telerik UI for ASP.NET AJAX is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-18935). Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.