Vulnerabilities in Progress Software

88 results
Vexday analysis

Progress Software apresenta uma taxa de exploração ativa 3,4 vezes acima da média geral do catálogo CISA KEV, sinalizando que, apesar do volume total de 65 CVEs catalogadas ser relativamente contido, a proporção de vulnerabilidades efetivamente exploradas merece atenção elevada. O caso mais crítico em exploração ativa é o CVE-2024-1212, com EPSS de 0,9539 — indicando probabilidade muito alta de exploração observada — e cuja natureza se enquadra no padrão mais frequente do vendor, o CWE-77 (injeção de comandos), tipo de falha que tipicamente permite execução arbitrária de código no contexto da aplicação. O surgimento de 20 CVEs nos últimos 90 dias representa uma cadência de divulgação acelerada que, combinada com 8 vulnerabilidades de severidade crítica e 2 com PoC pública disponível, amplia significativamente a superfície de ataque para equipes que ainda não aplicaram as correções disponíveis. Organizações que operam produtos Progress Software devem priorizar a remediação imediata das falhas críticas com PoC conhecida e monitorar ativamente o KEV para qualquer atualização no status de exploração.

CVE-2026-7312CRITICALCWE‑522: Insufficiently Protected Credentials in web services in Progress SitefinityEPSS 0.4%CVE-2026-14865MEDIUMXXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAXEPSS 0.4%CVE-2024-4837MEDIUMTrust Boundary Violation VulnerabilityEPSS 0.4%CVE-2024-8049MEDIUMTelerik Document Processing Improper Handling of Memory ResourcesEPSS 0.4%CVE-2026-9272HIGHPossibility of unintended database operations when querying data related to detected anomalies in Progress Flowmon ADSEPSS 0.4%CVE-2026-3692HIGHUnintended command execution during report generation in Progress FlowmonEPSS 0.4%CVE-2025-0332HIGHProgress UI for WinForms decompression path traversal vulnerabilityEPSS 0.4%CVE-2026-8486MEDIUMAllocation of resources without limits or throttling vulnerability in Progress Software MOVEit AutomationEPSS 0.4%CVE-2024-2291MEDIUMMOVEit Transfer Logging Bypass VulnerabilityEPSS 0.4%CVE-2024-11629HIGHTelerik Document Processing RTF Export of Arbitrary File PathEPSS 0.4%CVE-2025-10239HIGHUnintended command execution via troubleshooting scripts in Progress FlowmonEPSS 0.4%CVE-2025-6724HIGHChef Automate SQL Injection VulnerabilityEPSS 0.4%CVE-2026-8488MEDIUMAllocation of resources without limits or throttling vulnerability in Progress Software MOVEit AutomationEPSS 0.4%CVE-2026-18672HIGHRadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAXEPSS 0.4%CVE-2026-14932MEDIUMUnauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChartEPSS 0.4%CVE-2026-7201HIGHCWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress SitefinityEPSS 0.3%CVE-2026-8485MEDIUMUncontrolled Memory Allocation vulnerability in Progress Software MOVEit AutomationEPSS 0.3%CVE-2025-6505HIGHUnauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on LinuxEPSS 0.3%CVE-2026-8079HIGHUnintended limited set of actions with elevated privileges may be performed during PDF generation in Progress FlowmonEPSS 0.3%CVE-2025-10240HIGHPossibility of unintended actions when a user clicks a malicious link in the Progress Flowmon web applicationEPSS 0.3%