SecAlerts
P

Progress

Security Risk Profile

61
/100
high

Security Risk Score

Comprehensive risk assessment based on 323 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 2, 1999 to present

323
Total CVEs
244
Critical+High
14
Exploited
223
Unpatched

Threat Assessment

Avg CVSS
7.9
Base severity
Avg EPSS
3%
Exploit probability
Unpatched
223
Critical/High
Risk Level
61/100
high
⚠️ 14 Active Exploits 9 Zero-Days📈 9 in Last 30 Days

Severity Distribution

Critical
72
High
172
Medium
68
Low
0

Exploit Likelihood

>50% chance
2
20-50%
0
5-20%
1
<5%
74

Age Distribution

Common Weaknesses (CWE)

1
XSS
43
2
SQL Injection
28
3
Command Injection
27
4
OS Command Injection
26
5
Path Traversal
25

Most Affected Products

1. Progress MOVEit Transfer155
2. Progress Sitefinity112
3. Progress Ws Ftp Server90
4. Progress LoadMaster86
5. Progress WhatsUp Gold80

Recent Vulnerabilities

See more →
CVE-2026-18672
CVSS 7.5high

RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAX

Sep 2, 2026🔧 No Patch
CVE-2026-16137
CVSS 7.2high

Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller

Aug 17, 2026🔧 No Patch
CVE-2026-16138
CVSS 8.0high

Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO service

Aug 17, 2026🔧 No Patch
CVE-2026-16139
CVSS 7.2high

Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution

Aug 17, 2026🔧 No Patch
CVE-2026-65941
CVSS 8.8high

WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service.

Aug 12, 2026🔧 No Patch
CVE-2026-65940
CVSS 6.8medium

WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on the host server.

Aug 12, 2026🔧 No Patch
CVE-2026-65939
CVSS 6.8medium

WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.

Aug 12, 2026🔧 No Patch
CVE-2026-65938
CVSS 4.3medium

WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API.

Aug 12, 2026🔧 No Patch
CVE-2026-65937
CVSS 8.0high

WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UI

Aug 12, 2026🔧 No Patch
CVE-2026-9203
CVSS 8.5EPSS 0%high

Server-side request forgery in Progress MarkLogic Server

Aug 5, 2026🔧 No Patch

Monitor Progress in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.