Progress Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Progress products.
Products
- MOVEit Transfer22 vulnerabilities
- whatsup_gold21 vulnerabilities
- LoadMaster11 vulnerabilities
- telerik_reporting8 vulnerabilities
- ws_ftp_server6 vulnerabilities
- openedge5 vulnerabilities
- whatsupgold5 vulnerabilities
- ui_for_wpf4 vulnerabilities
- moveit_transfer3 vulnerabilities
- ShareFile Storage Zones Controller3 vulnerabilities
- sitefinity3 vulnerabilities
- WhatsUp Gold3 vulnerabilities
- DataDirect Connect for JDBC Autonomous REST Connector2 vulnerabilities
- DataDirect Connect for JDBC for Amazon Redshift2 vulnerabilities
- DataDirect Connect for JDBC for Apache Cassandra2 vulnerabilities
- DataDirect Connect for JDBC for Apache Impala2 vulnerabilities
- DataDirect Connect for JDBC for Apache SparkSQL2 vulnerabilities
- DataDirect Connect for JDBC for DB22 vulnerabilities
- DataDirect Connect for JDBC for Google Analytics 42 vulnerabilities
- DataDirect Connect for JDBC for Google BigQuery2 vulnerabilities
- DataDirect Connect for JDBC for Greenplum2 vulnerabilities
- DataDirect Connect for JDBC for Hive2 vulnerabilities
- DataDirect Connect for JDBC for Informix2 vulnerabilities
- DataDirect Connect for JDBC for Microsoft Dynamics 3652 vulnerabilities
- DataDirect Connect for JDBC for Microsoft Sharepoint2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-15968HIGH | Stored XSS vulnerability in MOVEit TransferImproper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. CWE-79Jul 23, 2026 | CVSS7.1v3.1 | EPSS0.181% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15967HIGH | MOVEit Transfer refresh-token processing does not enforce updated account restrictionsInsufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. CWE-613Jul 23, 2026 | CVSS7.5v3.1 | EPSS0.204% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15966HIGH | Improper CORS handling in MOVEit TransferPermissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. CWE-942Jul 23, 2026 | CVSS7.5v3.1 | EPSS0.204% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-10697HIGH | MFA Bypass in MOVEit TransferImproper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. CWE-287Jul 23, 2026 | CVSS7.5v3.1 | EPSS0.292% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15724HIGH | Path traversal in Progress ShareFile Storage Zones Controller (SZC)In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server. | CVSS8.7v3.1 | EPSS0.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
File Extension Restriction Bypass in MOVEit TransferPath equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4. CWE-46Jul 8, 2026 | CVSS3.5v3.1 | EPSS0.344% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Cross-Org External Token Metadata accessible to AuditUser roleIncorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. CWE-863Jul 8, 2026 | CVSS2.7v3.1 | EPSS0.209% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
IPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit TransferLimited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. CWE-290Jul 8, 2026 | CVSS3.7v3.1 | EPSS0.215% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-8650MEDIUM | Authenticated Path Traversal allows MOVEit admins to view arbitrary system filesRelative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. CWE-23Jul 8, 2026 | CVSS4.5v3.1 | EPSS0.365% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8649MEDIUM | Institution scope bypass vulnerability in custom reportsImproper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. CWE-943Jul 8, 2026 | CVSS6.4v3.1 | EPSS0.258% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11903HIGH | Stored XSS in MOVEit Transfer Ad Hoc moduleImproper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8. CWE-79Jul 8, 2026 | CVSS8.0v3.1 | EPSS0.281% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-10699HIGH | Memory leak in SFTP service can result in a denial of service in MOVEit TransferMissing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1. CWE-401Jul 8, 2026 | CVSS7.5v3.1 | EPSS0.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-10698HIGH | Table scope bypass vulnerability in custom reportsImproper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1. CWE-943Jul 8, 2026 | CVSS7.2v3.1 | EPSS0.496% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8037CRITICAL | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAFOS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints | CVSS9.6v3.1 | EPSS99.3% | PoCs2 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-2701CRITICAL | RCE vulnerability in Progress ShareFile Storage Zones Controller (SZC)Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. | CVSS9.1v3.1 | EPSS56.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2699CRITICAL | EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution. | CVSS9.8v3.1 | EPSS58.4% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
MOVEit Transfer REST API does not require current password in order to initiate the password change processUnverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10. CWE-620Jan 6, 2026 | CVSS3.7v3.1 | EPSS0.185% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-13147MEDIUM | External Service Interaction (DNS)Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before 2024.1.8, from 2025.0.0 before 2025.0.4. CWE-918Nov 19, 2025 | CVSS5.3v3.1 | EPSS0.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-10703HIGH | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver log=(file) construct allows the user to specify an arbitrary file for the JDBC driver to write its log… CWE-94Nov 19, 2025 | CVSS8.6v4.0 | EPSS0.292% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-10702HIGH | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver supports an undocumented syntax construct for the option value that if discovered can be used by an a… CWE-94Nov 19, 2025 | CVSS8.6v4.0 | EPSS0.292% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-10932HIGH | AS2 module allows uncontrolled file uploadsUncontrolled Resource Consumption vulnerability in Progress MOVEit Transfer (AS2 module).This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.3, from 2024.1.0 before 2024.1.7, from 2023.1.0 before 2023.1.16. CWE-400Oct 29, 2025 | CVSS8.2v3.1 | EPSS0.477% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-1758MEDIUM | Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above CWE-121Mar 19, 2025 | CVSS4.3v3.1 | EPSS4.79% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-2324MEDIUM | A MOVEit Transfer user configured as a Shared Account can gain unintended List permissions on a folderImproper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before 2024.1.2. CWE-269Mar 19, 2025 | CVSS5.9v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-56135HIGH | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1 (inclusive) CWE-20Feb 5, 2025 | CVSS8.4v3.1 | EPSS0.591% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-56134HIGH | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12 and all prior versions ECS All prior versions to 7.2.60.1 (inclusive) CWE-20Feb 5, 2025 | CVSS8.4v3.1 | EPSS0.591% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |