PatchSiren

Progress Software CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Progress Software CVE published 2026-08-07

CVE-2026-8037

CVE-2026-8037 is a critical OS Command Injection Remote Code Execution Vulnerability in the API of Progress ADC Products. This vulnerability allows an unauthenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. The vulnerability has a CVSS score of 9.6, indicating a critical severity level.

HIGH Progress Software CVE published 2026-07-27

CVE-2026-59690

A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise. The vulnerability has a CVSS s [truncated]

HIGH Progress Software CVE published 2026-07-27

CVE-2026-59689

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise. This vulnerability has a high CVSS score of 8, indicating high severity. Users of these products shoul [truncated]

HIGH Progress Software CVE published 2026-07-27

CVE-2026-59688

CVE-2026-59688 is an OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. An authenticated attacker with high privileges can execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise. The vulnerability has a CVSS score [truncated]

HIGH Progress Software CVE published 2026-07-27

CVE-2026-59687

CVE-2026-59687 is an OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. An authenticated attacker with high privileges can execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise. The CVSS score for this vulne [truncated]

HIGH Progress Software CVE published 2026-07-27

CVE-2026-59686

CVE-2026-59686 is an OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. An authenticated attacker with high privileges can execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise. The vulnerability has a high severity with [truncated]

MEDIUM Progress Software CVE published 2026-07-22

CVE-2026-14932

A vulnerability was found in Progress Telerik UI for AJAX prior to v2026.2.708. The obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory. This issue arises from the ChartImage.axd handler allowing unauthenticated access, which can lead to unauthorized file operations. Users of Progress Telerik [truncated]

MEDIUM Progress Software CVE published 2026-07-22

CVE-2026-14865

CVE-2026-14865 is a denial of service vulnerability in Progress Telerik UI for AJAX prior to v2026.2.708. The internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Users of Progress Telerik UI for AJAX prior to v2026.2.708 [truncated]

MEDIUM Progress Software CVE published 2026-07-22

CVE-2026-13192

CVE-2026-13192 is a vulnerability in Progress Telerik UI for AJAX prior to v2026.2.708, specifically in the RadEditor PDF export feature. Insufficient validation of content submitted to this feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication credentials. This vulnerabilit [truncated]

HIGH Progress Software CVE published 2026-07-22

CVE-2026-13190

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:14.667Z and has not been modified since then. CVE-2026-13190 is a deserialization vulnerability in Progress Telerik UI for AJAX prior to v2026.2.708. The vulnerability allows for unsafe type instantiation from attacker-influenced persisted state, potentially leading to remote code execution [truncated]

HIGH Progress Software CVE published 2026-07-22

CVE-2026-13189

In Progress Telerik UI for AJAX prior to v2026.2.708, a vulnerability exists due to insufficient validation of the language parameter in the spell check handler. This may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests. The CVE record was published on 2026-07-22T14:17:14.537Z and has not been modified since then. Users should verify their systems [truncated]

MEDIUM Progress Software CVE published 2026-07-22

CVE-2026-13188

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:14.417Z and has not been modified since then. Progress Telerik UI for AJAX prior to v2026.2.708 is vulnerable to tampering with DialogHandler request parameters, potentially altering dialog server-side behavior and enabling chained exploitation. Users should review and apply the vendor's re [truncated]

HIGH Progress Software CVE published 2026-07-22

CVE-2026-13187

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:14.300Z and has not been modified since then. Progress Telerik UI for AJAX prior to v2026.2.708 is vulnerable to tampering with DialogHandler provider type input, potentially altering dialog processing and enabling chained exploitation. This HIGH severity vulnerability has a CVSS score of 8 [truncated]

HIGH Progress Software CVE published 2026-07-22

CVE-2026-13186

The CVE-2026-13186 vulnerability is a path traversal issue in Progress Telerik UI for AJAX prior to v2026.2.708. This vulnerability can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution. Organizations should review their deployments and assess potential impact. The vulnerability has a high severity level with a C [truncated]

HIGH Progress Software CVE published 2026-07-22

CVE-2026-13184

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:13.927Z and has not been modified since then. This vulnerability affects Progress Telerik UI for AJAX prior to v2026.2.708, allowing attackers to forge protected upload metadata when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured.

HIGH Progress Software CVE published 2026-07-22

CVE-2026-13183

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:13.807Z and has not been modified since then. This HIGH-severity vulnerability in Progress Telerik UI for AJAX RadAsyncUpload allows remote attackers to recover protected metadata values through measurable timing differences in upload metadata processing. Users of Progress Telerik UI for AJ [truncated]

HIGH Progress Software CVE published 2026-07-22

CVE-2026-13182

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:13.683Z and has not been modified since then. Progress Telerik UI for AJAX versions prior to v2026.2.708 contain a vulnerability in RadAsyncUpload client-state processing. This vulnerability allows remote attackers to distinguish decrypt failures from invalid-JSON parse failures, creating a [truncated]

HIGH Progress Software CVE published 2026-07-22

CVE-2026-13181

CVE-2026-13181 is a high-severity remote code execution vulnerability in Progress Telerik UI for AJAX versions prior to v2026.2.708. The vulnerability is caused by forged upload metadata influencing AsyncUploadTypeName processing, triggering unsafe attacker-controlled type resolution. This type of vulnerability typically allows attackers to execute arbitrary code on the affected system, potentially leadin [truncated]

MEDIUM Progress Software CVE published 2026-05-20

CVE-2026-8488

CVE-2026-8488 is a medium-severity availability issue in Progress Software MOVEit Automation. The published record describes an allocation-of-resources-without-limits-or-throttling weakness (CWE-770), which can lead to excessive allocation and service degradation if left unpatched. NVD lists the issue as affecting MOVEit Automation before 2025.0.11 and from 2025.1.0 before 2025.1.7.

MEDIUM Progress Software CVE published 2026-05-20

CVE-2026-8487

CVE-2026-8487 is an incorrect default permissions issue affecting Progress Software MOVEit Automation. According to the official NVD summary and Progress release notes reference, the flaw can allow retrieval of embedded sensitive data and affects MOVEit Automation versions before 2025.0.11 and from 2025.1.0 before 2025.1.7. The published CVSS 3.1 vector indicates network access, low attack complexity, low [truncated]

MEDIUM Progress Software CVE published 2026-05-20

CVE-2026-8486

CVE-2026-8486 is a medium-severity availability flaw in Progress Software MOVEit Automation. The issue is described as allocation of resources without limits or throttling, which can allow flooding and degrade service availability. The affected ranges listed in the CVE are versions before 2025.0.11 and versions from 2025.1.0 before 2025.1.7. The NVD record currently lists the vulnerability status as under [truncated]

MEDIUM Progress Software CVE published 2026-05-20

CVE-2026-8485

CVE-2026-8485 is a medium-severity Progress MOVEit Automation issue caused by uncontrolled memory allocation, which can lead to excessive allocation and availability loss. The vulnerability was publicly recorded on 2026-05-20 and affects MOVEit Automation releases before 2025.0.11 and from 2025.1.0 before 2025.1.7. The supplied CVSS vector indicates a network-reachable issue with no privileges or user int [truncated]

HIGH Progress Software CVE published 2026-01-13

CVE-2025-13444

CVE-2025-13444 is an OS Command Injection Remote Code Execution Vulnerability in the API of Progress LoadMaster. An authenticated attacker with 'User Administration' permissions can exploit unsanitized input in API parameters to execute arbitrary commands on the LoadMaster appliance. The vulnerability has a CVSS score of 8.4 and is classified as HIGH severity. Affected product deployments should be identi [truncated]