PatchSiren

Progress CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Progress CVE published 2026-07-23

CVE-2026-15968

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T21:17:03.090Z and has not been modified since then. This cross-site scripting vulnerability affects Progress MOVEit Transfer, specifically versions before 2025.1.5 and from 2026.0.0 before 2026.0.3. Organizations should be aware of the potential for cross-site scripting attacks and take steps to [truncated]

HIGH Progress CVE published 2026-07-23

CVE-2026-15967

CVE-2026-15967 is an Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. The vulnerability has a CVSS score of 7.5 and a severity of HIGH. Security teams and administrators responsible for Progress MOVEit Transfer installations should be aware of this vulnerability and take necessary actions to mitig [truncated]

HIGH Progress CVE published 2026-07-23

CVE-2026-15966

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T21:17:02.860Z and has not been modified since then. This vulnerability affects Progress MOVEit Transfer, specifically versions before 2025.1.5 and from 2026.0.0 before 2026.0.3. The vulnerability is a permissive cross-domain security policy with untrusted domains, which has a CVSS score of 7.5 an [truncated]

HIGH Progress CVE published 2026-07-23

CVE-2026-10697

CVE-2026-10697 is an Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. According to the CVE record, the vulnerability has a CVSS score of 7.5 and a severity of HIGH. The vulnerability could allow an attacker to gain unauthorized access to the system, potentially leading to data breaches or system compromis [truncated]

HIGH Progress CVE published 2026-07-21

CVE-2026-15724

CVE-2026-15724 is a path traversal vulnerability in Progress ShareFile Storage Zones Controller. Authenticated administrative users can exploit this HIGH-severe vulnerability to read arbitrary files, write files to arbitrary directories, or determine whether specific files exist on the server filesystem. The vulnerability has a CVSS score of 8.7, indicating a HIGH severity level. Administrators and users [truncated]

MEDIUM Progress CVE published 2026-07-08

CVE-2026-8649

CVE-2026-8649 is an Improper Neutralization of Special Elements in Data Query Logic vulnerability affecting Progress MOVEit Transfer's Custom Reports modules. This issue impacts MOVEit Transfer versions before 2025.0.7 and from 2025.1.0 before 2025.1.3. The vulnerability has a CVSS score of 6.4, indicating medium severity. The CVE record was published on 2026-07-08T20:17:00.557Z and last modified on 2026- [truncated]

HIGH Progress CVE published 2026-07-08

CVE-2026-11903

CVE-2026-11903 is a high-severity cross-site scripting vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer versions from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, and from 2025.0.0 before 2025.0.8. The vulnerability has a CVSS score of 8 and is classified as HIGH. The vulnerability is caused by improper neutralization of input during web page generation, allowing f [truncated]

HIGH Progress CVE published 2026-07-08

CVE-2026-10699

A high-severity vulnerability was found in Progress MOVEit Transfer, affecting versions from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, and from 2026.0.0 before 2026.0.1. This issue is related to a missing release of memory after its effective lifetime, which could potentially lead to security issues. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. It affects th [truncated]

HIGH Progress CVE published 2026-07-08

CVE-2026-10698

CVE-2026-10698 is an Improper Neutralization of Special Elements in Data Query Logic vulnerability affecting Progress MOVEit Transfer versions from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, and from 2026.0.0 before 2026.0.1. This issue has a CVSS score of 7.2 and is classified as HIGH severity. The vulnerability exists in the Custom Reports modules of Progress MOVEit Transfer, allowing atta [truncated]

HIGH Progress CVE published 2026-07-02

CVE-2026-9272

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, allowing an authenticated low-privileged user to send specially crafted requests, potentially resulting in unauthorized access to application data and its modification. This issue has a high CVSS score of 8.7, indicating a critical severity level. Security teams and administrators responsible for Progress Flowmon ADS shoul [truncated]

Known exploited Progress CVE published 2025-03-03

CVE-2024-4885

CVE-2024-4885 is a path traversal vulnerability in Progress WhatsUp Gold that CISA added to the Known Exploited Vulnerabilities catalog on 2025-03-03. Because it is already tracked as known exploited, organizations should treat it as an urgent remediation item and follow vendor guidance without delay.

Known exploited Progress CVE published 2024-11-18

CVE-2024-1212

CVE-2024-1212 is a Progress Kemp LoadMaster OS command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-11-18. Because it is KEV-listed, defenders should treat Kemp LoadMaster deployments as a priority and follow vendor mitigation guidance promptly.

Known exploited Progress CVE published 2024-09-16

CVE-2024-6670

CVE-2024-6670 is a SQL injection vulnerability in Progress WhatsUp Gold that CISA lists in the Known Exploited Vulnerabilities catalog. CISA also notes known ransomware campaign use, which makes this a time-sensitive issue for any organization running the product. Follow vendor mitigation guidance immediately, or discontinue use if mitigations are not available.

Known exploited Progress CVE published 2024-06-13

CVE-2024-4358

CVE-2024-4358 affects Progress Telerik Report Server and is described as an authentication bypass by spoofing issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-06-13, which means it is considered actively exploited. The safest defensive response is to follow vendor mitigation guidance immediately; if mitigations are unavailable, CISA advises discontinuing use of the product.

Known exploited Progress CVE published 2023-10-05

CVE-2023-40044

CVE-2023-40044 is a Progress WS_FTP Server deserialization of untrusted data issue that CISA added to its Known Exploited Vulnerabilities catalog on 2023-10-05. Because it is listed as known exploited and marked for known ransomware campaign use, organizations should treat it as a high-priority remediation item and follow vendor guidance immediately.

Known exploited Progress CVE published 2023-06-02

CVE-2023-34362

CVE-2023-34362 is a SQL injection vulnerability in Progress MOVEit Transfer. CISA added it to the Known Exploited Vulnerabilities catalog on the same date it was published and marked it as known exploited, with known ransomware campaign use.

Known exploited Progress CVE published 2021-11-03

CVE-2019-18935

CVE-2019-18935 is a Progress Telerik UI for ASP.NET AJAX vulnerability involving deserialization of untrusted data. CISA has listed it in the Known Exploited Vulnerabilities catalog and marked it as having known ransomware campaign use, which makes it a priority issue for defenders running the affected product.

Known exploited Progress CVE published 2021-11-03

CVE-2017-9248

CVE-2017-9248 is a cryptographic weakness affecting Progress Telerik UI for ASP.NET AJAX and Sitefinity. CISA lists it in the Known Exploited Vulnerabilities catalog, which means it has been observed in active exploitation and should be treated as a priority remediation item. The source corpus directs organizations to apply updates per vendor instructions.