Vulnerabilities in Progress Software

85 results
Vexday analysis

Progress Software apresenta uma taxa de exploração ativa 3,4 vezes acima da média geral do catálogo CISA KEV, sinalizando que, apesar do volume total de 65 CVEs catalogadas ser relativamente contido, a proporção de vulnerabilidades efetivamente exploradas merece atenção elevada. O caso mais crítico em exploração ativa é o CVE-2024-1212, com EPSS de 0,9539 — indicando probabilidade muito alta de exploração observada — e cuja natureza se enquadra no padrão mais frequente do vendor, o CWE-77 (injeção de comandos), tipo de falha que tipicamente permite execução arbitrária de código no contexto da aplicação. O surgimento de 20 CVEs nos últimos 90 dias representa uma cadência de divulgação acelerada que, combinada com 8 vulnerabilidades de severidade crítica e 2 com PoC pública disponível, amplia significativamente a superfície de ataque para equipes que ainda não aplicaram as correções disponíveis. Organizações que operam produtos Progress Software devem priorizar a remediação imediata das falhas críticas com PoC conhecida e monitorar ativamente o KEV para qualquer atualização no status de exploração.

CVE-2024-1212CRITICALLoadMaster Pre-Authenticated OS Command InjectionEPSS 95.4%KEVCVE-2024-2389CRITICALFlowmon Unauthenticated Command Injection VulnerabilityEPSS 92.9%CVE-2026-8037CRITICALOS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAFEPSS 84.8%CVE-2024-2448HIGHLoadMaster Command Injection VulnerabilityEPSS 55.4%CVE-2025-13447HIGHOS Command Injection Remote Code Execution Vulnerability in Progress LoadMasterEPSS 25.4%CVE-2025-13444HIGHOS Command Injection Remote Code Execution Vulnerability in Progress LoadMasterEPSS 25.4%CVE-2025-8868CRITICALChef Automate compliance service SQL Injection VulnerabilityEPSS 22.8%CVE-2025-3600HIGHUnsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAXEPSS 20.0%CVE-2026-3518HIGHOS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAFEPSS 19.9%CVE-2026-3517HIGHOS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAFEPSS 18.2%CVE-2024-2449HIGHLoadMaster Cross-Site Request Forgery (CSRF)EPSS 12.9%CVE-2026-4670CRITICALImproper Authentication vulnerability in Progress MOVEit AutomationEPSS 5.6%CVE-2026-5174HIGHImproper Access Control Vulnerability in Progress MOVEit AutomationEPSS 3.2%CVE-2026-3519HIGHOS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAFEPSS 2.1%CVE-2026-4048HIGHOS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAFEPSS 2.1%CVE-2024-8015CRITICALTelerik Report Server Insecure Type ResolutionEPSS 0.8%CVE-2024-7679HIGHImproper neutralization special element in hyperlinksEPSS 0.7%CVE-2024-10095HIGHProgress UI for WPF format provider unsafe deserialization vulnerabilityEPSS 0.7%CVE-2026-59686HIGHProgress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management InterfaceEPSS 0.7%CVE-2026-59688HIGHProgress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore FunctionalityEPSS 0.7%