Skip to content

Progress Software security advisories

54 advisories · 42 critical or high in 12 months · latest Sep 11

54 advisories

Advisory
Progress Software Chef Automate: missing authentication
Critical10.0Sep 11
Progress Software Telerik UI for ASP.NET AJAX: remote code execution
High8.1Sep 2
Progress Software Telerik UI for ASP.NET AJAX: path traversal
High7.5Sep 2
Progress Software ShareFile Storage Zones Controller: path traversal
High7.2Aug 17
Progress Software ShareFile Storage Zones Controller: unsafe deserialization
High8.0Aug 17
Progress Software ShareFile Storage Zones Controller: remote code execution
High7.2Aug 17
Progress Software WhatsUp Gold: remote code execution
High8.8Aug 12
Progress Software WhatsUp Gold: cross-site scripting
High8.0Aug 12
Progress Software WhatsUp Gold: improper authorization
Medium4.3Aug 12
Progress Software WhatsUp Gold: path traversal
Medium6.8Aug 12
Progress Software WhatsUp Gold: insecure default permissions
Medium6.8Aug 12
Progress Software MarkLogic Server: authentication bypass
Critical9.8Aug 5
Progress Software MarkLogic Server: privilege escalation
Critical9.9Aug 5
Progress Software MarkLogic Server: cross-site scripting
Critical9.3Aug 5
Progress Software MarkLogic Server: server-side request forgery
High8.5Aug 5
Progress Software MarkLogic Server: privilege escalation
High8.1Aug 5
Progress Software MarkLogic Server: privilege escalation
Critical9.9Aug 5
Progress Software MarkLogic Server: authentication bypass
Critical9.1Aug 5
Progress Software MarkLogic Server: privilege escalation
Critical9.9Aug 5
Progress Software MarkLogic Server: request smuggling
Critical9.1Aug 5
Progress Software MarkLogic Server: cross-site request forgery
High7.5Aug 5
Progress Software ECS Connection Manager: command injection
High8.4Jul 27
Progress Software ECS Connection Manager: command injection
High8.4Jul 27
Progress Software ECS Connection Manager: improper authorization
High8.0Jul 27
Progress Software ECS Connection Manager: missing authorization
High8.0Jul 27
Progress Software ECS Connection Manager: command injection
High8.4Jul 27
Progress Software MOVEit Transfer: cross-site scripting
High7.1Jul 23
Permissive cross-domain security policy with untrusted domains vulnerability in...
High7.5Jul 23
Progress Software MOVEit Transfer: insufficient session expiration
High7.5Jul 23
Progress Software MOVEit Transfer: improper authentication
High7.5Jul 23
Progress Software Telerik UI for ASP.NET AJAX: denial of service
Medium5.3Jul 22
Progress Software Telerik UI for ASP.NET AJAX: hard-coded key
Medium6.5Jul 22
Progress Software Telerik UI for ASP.NET AJAX: remote code execution
High8.1Jul 22
Progress Software Telerik UI for ASP.NET AJAX: path traversal
High8.1Jul 22
In Progress Telerik UI for AJAX prior to v2026.2.708
High8.1Jul 22
Progress Software Telerik UI for ASP.NET AJAX: insufficient authenticity check
Medium5.9Jul 22
Progress Software Telerik UI: attacker could influence server-side file path...
High7.5Jul 22
Progress Software Telerik UI for ASP.NET AJAX: unsafe deserialization
High8.1Jul 22
Progress Software Telerik UI for ASP.NET AJAX: server-side request forgery
Medium6.5Jul 22
Progress Software Telerik UI for ASP.NET AJAX: remote code execution
High8.1Jul 22
Progress Software Telerik UI for ASP.NET AJAX: information disclosure in errors
High7.5Jul 22
In Progress Telerik UI for AJAX prior to v2026.2.708
High7.5Jul 22
Progress Software Telerik UI for ASP.NET AJAX: hard-coded key
High7.5Jul 22
Progress Software ShareFile Storage Zones Controller: path traversal
High8.7Jul 21
Path equivalence: vulnerability in Progress MOVEit Transfer
Low3.5Jul 8
Improper Neutralization of Special Elements in Data Query Logic vulnerability...
Medium6.4Jul 8
Progress Software MOVEit Transfer: path traversal
Medium4.5Jul 8
Progress Software MOVEit Transfer: authentication bypass
Low3.7Jul 8
Progress Software MOVEit Transfer: improper authorization
Low2.7Jul 8
Improper Neutralization of Special Elements in Data Query Logic vulnerability...
High7.2Jul 8
Progress Software MOVEit Transfer: memory leak
High7.5Jul 8
Progress Software MOVEit Transfer: cross-site scripting
High8.0Jul 8
Progress Software Flowmon: improper authorization
High8.7Jul 2
Progress Software Flowmon ADS: SQL injection
High8.7Jul 2
About Progress Software

Security advisories Progress Software publishes for its own products.

Progress Software elsewhere on fru.dev: Acquisitions · Quarterly · Paydays

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.