Progress Software Corporation Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Progress Software Corporation products.
Products
- WhatsUp Gold42 vulnerabilities
- WS_FTP Server11 vulnerabilities
- MarkLogic Server10 vulnerabilities
- Sitefinity7 vulnerabilities
- Telerik Report Server7 vulnerabilities
- MOVEit Transfer6 vulnerabilities
- OpenEdge5 vulnerabilities
- Telerik Reporting5 vulnerabilities
- LoadMaster2 vulnerabilities
- Chef Automate1 vulnerability
- Chef Habitat Builder1 vulnerability
- Chef InSpec1 vulnerability
- MOVEit Automation1 vulnerability
- Progress® Telerik® Reporting1 vulnerability
- Telerik UI for WinForms1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-65941HIGH | WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service.In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account. | CVSS8.8v3.1 | EPSS0.437% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65940MEDIUM | WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on the host server.In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. | CVSS6.8v3.1 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65939MEDIUM | WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root. | CVSS6.8v3.1 | EPSS0.238% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65938MEDIUM | WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API.In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions. | CVSS4.3v3.1 | EPSS0.161% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65937HIGH | WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UIIn WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content. CWE-79Aug 12, 2026 | CVSS8.0v3.1 | EPSS0.242% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9203HIGH | Server-side request forgery in Progress MarkLogic ServerA server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance. CWE-918Aug 5, 2026 | CVSS8.5v3.1 | EPSS0.212% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9195CRITICAL | Cross-site scripting in Progress MarkLogic Server Query ConsoleA cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the administrator's behalf. | CVSS9.3v3.1 | EPSS0.388% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9193CRITICAL | Privilege escalation in Progress MarkLogic Server Hadoop integrationAn improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database. CWE-269Aug 5, 2026 | CVSS9.9v3.1 | EPSS0.257% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9192CRITICAL | Authentication bypass in Progress MarkLogic Server ODBC App ServerAn authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators. CWE-287Aug 5, 2026 | CVSS9.8v3.1 | EPSS0.473% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9190CRITICAL | HTTP request smuggling in Progress MarkLogic ServerAn HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently. CWE-444Aug 5, 2026 | CVSS9.1v3.1 | EPSS0.422% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8709CRITICAL | Privilege escalation in Progress MarkLogic Server REST document patch operationAn improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database. CWE-269Aug 5, 2026 | CVSS9.9v3.1 | EPSS0.257% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7557CRITICAL | SAML authentication bypass in Progress MarkLogic ServerAn improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled. CWE-347Aug 5, 2026 | CVSS9.1v3.1 | EPSS0.266% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7329CRITICAL | Privilege escalation in Progress MarkLogic Server REST query interfacesAn improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access. CWE-269Aug 5, 2026 | CVSS9.9v3.1 | EPSS0.317% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7327HIGH | Privilege escalation in Progress MarkLogic Server REST API document processingAn improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user. CWE-269Aug 5, 2026 | CVSS8.1v3.1 | EPSS0.222% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7326HIGH | Cross-site request forgery in Progress MarkLogic Server Admin UIA cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration. CWE-352Aug 5, 2026 | CVSS7.5v3.1 | EPSS0.137% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-8095CRITICAL | Recoverable obfuscation using the OECH1 prefix encoding in OpenEdgeThe OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications. OECH1 encodings should be considered exploitable and immediately replaced by any other supported prefix encoding, all of which are based on symmetric encryption. CWE-257Apr 14, 2026 | CVSS9.1v4.0 | EPSS0.216% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-7389HIGH | Unauthorized Arbitrary File Read via RMI in AdminServer InterfaceA vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server through the adopted authority of the AdminServer process itself. The delegated authority of the AdminServer could allow its users the ability to read arbitrary files on the host system through the misuse of the setFile() and openFile() methods exposed through the RMI interface. Misuse was limited only by OS-level authority of the AdminServer's elevat… CWE-552Apr 14, 2026 | CVSS8.2v4.0 | EPSS0.326% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-7388HIGH | Authenticated Command Injection via configuration parameter manipulation in exposed RMI interfaceIt was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and execute OS commands under the delegated authority of the AdminServer process. An RMI interface permitted manipulation of a configuration property with inadequate input validation leading to OS command injection. CWE-77Sep 4, 2025 | CVSS8.4v3.1 | EPSS0.925% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-2572MEDIUM | WhatsUp Gold NmConfigurationManager.exe database manipulation vulnerabilityIn WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup. CWE-287Apr 14, 2025 | CVSS5.6v3.1 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-1968HIGH | Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncommon circumstances allows reusing Session IDs (Session Replay Attacks).This issue affects Sitefinity: from 14.0 through 14.3, from 14.4 before 14.4.8145, from 15.0 before 15.0.8231, from 15.1 before 15.1.8332, from 15.2 before 15.2.8429. CWE-613Apr 9, 2025 | CVSS7.7v3.1 | EPSS0.305% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6097MEDIUM | Absolute Path Traversal VulnerabilityIn Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability. | CVSS5.3v3.1 | EPSS0.492% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-11626HIGH | Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421. CWE-79Jan 7, 2025 | CVSS8.4v3.1 | EPSS0.357% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-11625HIGH | Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421. CWE-209Jan 7, 2025 | CVSS7.7v3.1 | EPSS0.296% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-12105MEDIUM | WhatsUp Gold - SnmpExtendedActiveMonitor path traversalIn WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure. CWE-22Dec 31, 2024 | CVSS6.5v3.1 | EPSS42.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-12106CRITICAL | WhatsUp Gold - LDAP configuration interface leading to allowing attacker to configure LDAP settings without authenticationIn WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings. CWE-306Dec 31, 2024 | CVSS9.4v3.1 | EPSS9.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |