CVE Tools

Progress-software

41 CVEs tracked since 2024. Since Sep 2024, none of them reached CISA KEV.

Progress-software CVEs per month

Sep 2024 to Jul 2026. Point at a month, or focus the strip and use the arrow keys.
Progress-software CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-0940
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-0270
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04100
2026-05null or fewer
2026-06null or fewer
2026-07200

Products

The products that kept showing up in Progress-software's monthly top three, with their CVEs summed over those months.

  1. Telerik Ui For Asp.net Ajax131 month
  2. Object Scale Connection Manager92 months
  3. Ecs Connection Manager51 month
  4. Loadmaster41 month
  5. Moveit Waf41 month
  6. Telerik Ui For Wpf31 month
  7. Progress® Telerik® Document Processing Libraries11 month
  8. Progress® Telerik® Kendo Ui For Vue11 month
  9. Progress® Telerik® Ui For Winforms11 month
  10. Telerik Ui For Winforms11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Progress-software.

  1. CVE-2026-80462Privilege Escalation in Progress Chef Automate10.0
  2. CVE-2026-19219DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX8.1
  3. CVE-2026-18672RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAX7.5
  4. CVE-2026-59690Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API8.0
  5. CVE-2026-59689Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root8.0
  6. CVE-2026-59688Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality8.4
  7. CVE-2026-59687Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface8.4
  8. CVE-2026-59686Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface8.4
  9. CVE-2026-14932Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart6.5
  10. CVE-2026-14865XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX5.3
  11. CVE-2026-13192RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX6.5
  12. CVE-2026-13190PersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX8.1
  13. CVE-2026-13189SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX7.5
  14. CVE-2026-13188DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX5.9
  15. CVE-2026-13187DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET AJAX8.1

The record

Peak rank
#60 in Jul 2026
Busiest month shown
Jul 2026, 20 CVEs
Months with a KEV entry
0 since Sep 2024
Monthly snapshots
4 since 2024
Progress-software's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store