Skip to content
Threat Feed

Vendor

Progress

7 briefs RSS
high advisory

Multiple Critical Vulnerabilities in Progress Telerik UI for ASP.NET AJAX

Progress Telerik UI for ASP.NET AJAX is affected by a suite of thirteen critical vulnerabilities, including insecure deserialization, path traversal, XXE, and SSRF, which collectively enable remote code execution and data theft.

Telerik UI for ASP.NET AJAX vulnerability web-application rce srf
2t 5c
high advisory

Critical Security Vulnerabilities in Progress MarkLogic Server

Progress Software has released a security bulletin addressing ten critical vulnerabilities, including CVE-2026-7326 through CVE-2026-9203, affecting MarkLogic Server versions prior to 11.3.6 and 12.0.3.

MarkLogic Server vulnerability security-advisory patch-management
5c 2i
high advisory

Multiple Vulnerabilities in Progress MOVEit Transfer

Multiple vulnerabilities, including remote XSS and security policy bypass, have been identified in Progress MOVEit Transfer versions prior to 2026.0.3, enabling potential unauthorized access and session-based script execution.

MOVEit Transfer vulnerability web-application moveit
1t 4c
high advisory

Progress MOVEit Transfer Critical Security Advisory (AV26-678)

Progress Software has issued a critical security advisory (AV26-678) detailing multiple vulnerabilities, including CVE-2026-10699, CVE-2026-10698, and CVE-2026-11903, affecting various versions of its MOVEit Transfer product, necessitating immediate patching to prevent potential exploitation.

MOVEit Transfer +3 vulnerability cve data-exfiltration critical-vulnerability moveit
3c
critical advisory

Progress Security Advisory (AV26-552) Addressing Multiple Critical Vulnerabilities

Progress released critical security advisories between June 2 and 4, 2026, addressing multiple vulnerabilities, including CVE-2026-7312, CVE-2026-7198, CVE-2026-7195, CVE-2026-7201, CVE-2026-7313, CVE-2026-8037, and CVE-2026-33691, in Sitefinity CMS, Sitefinity Insight, and Progress Kemp LoadMaster, which could lead to various impacts if exploited, necessitating immediate patching.

PoC Sitefinity CMS +9 vulnerability web-application cms load-balancer patch-management cve
3r 1t 5c 4i updated
high advisory

Multiple Vulnerabilities in Progress MOVEit Automation

Multiple vulnerabilities in Progress MOVEit Automation allow for remote denial of service, security policy bypass, and unspecified security issues.

MOVEit Automation +1 vulnerability dos security-bypass
2r 2t 4c
critical advisory

WS_FTP Remote Code Execution Vulnerability (CVE-2023-40044)

Exploitation attempts targeting CVE-2023-40044 in WS_FTP software can lead to remote code execution via crafted HTTP POST requests, potentially allowing attackers to gain unauthorized access and compromise the affected system.

WS_FTP Server ws_ftp rce cve-2023-40044 webserver
2r 1t