{"schema_version":1,"title":"Progress Software vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 17 vulnerabilities in Progress Software: 0 in the last 7 days and 11 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-59690, was published on 27 July 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/progress-software","json_url":"https://junglewise.ai/threats/vendors/progress-software.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/progress-software","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":6,"all_time":17,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":11,"last_365_days":17},"latest":[{"cve":"CVE-2026-59690","cvss":8,"slug":"cve-2026-59690-progress-software-loadmaster-missing-authorization-in-rest-api","title":"Progress Software LoadMaster missing authorization in REST API","severity":"high","exploited":false,"published_at":"2026-07-27T13:18:22.457+00:00","url":"https://junglewise.ai/threats/cve-2026-59690-progress-software-loadmaster-missing-authorization-in-rest-api"},{"cve":"CVE-2026-14932","cvss":6.5,"slug":"cve-2026-14932-progress-telerik-ui-for-asp-net-ajax-file-read-and-deletion-in","title":"Progress Telerik UI for ASP.NET AJAX file read and deletion in RadChart","severity":"medium","exploited":false,"published_at":"2026-07-22T14:17:15.283+00:00","url":"https://junglewise.ai/threats/cve-2026-14932-progress-telerik-ui-for-asp-net-ajax-file-read-and-deletion-in"},{"cve":"CVE-2026-14865","cvss":5.3,"slug":"cve-2026-14865-progress-telerik-ui-for-ajax-denial-of-service-in-layoutbuilder","title":"Progress Telerik UI for AJAX denial of service in LayoutBuilder","severity":"medium","exploited":false,"published_at":"2026-07-22T14:17:15.163+00:00","url":"https://junglewise.ai/threats/cve-2026-14865-progress-telerik-ui-for-ajax-denial-of-service-in-layoutbuilder"},{"cve":"CVE-2026-13192","cvss":6.5,"slug":"cve-2026-13192-progress-telerik-ui-for-asp-net-ajax-ssrf-in-radeditor-pdf-export","title":"Progress Telerik UI for ASP.NET AJAX SSRF in RadEditor PDF export","severity":"medium","exploited":false,"published_at":"2026-07-22T14:17:14.777+00:00","url":"https://junglewise.ai/threats/cve-2026-13192-progress-telerik-ui-for-asp-net-ajax-ssrf-in-radeditor-pdf-export"},{"cve":"CVE-2026-13190","cvss":8.1,"slug":"cve-2026-13190-progress-telerik-ui-for-asp-net-ajax-deserialization-in","title":"Progress Telerik UI for ASP.NET AJAX deserialization in PersistenceFramework","severity":"high","exploited":false,"published_at":"2026-07-22T14:17:14.667+00:00","url":"https://junglewise.ai/threats/cve-2026-13190-progress-telerik-ui-for-asp-net-ajax-deserialization-in"},{"cve":"CVE-2026-13189","cvss":7.5,"slug":"cve-2026-13189-progress-telerik-ui-for-asp-net-ajax-path-traversal-in-spell","title":"Progress Telerik UI for ASP.NET AJAX path traversal in spell check handler","severity":"high","exploited":false,"published_at":"2026-07-22T14:17:14.537+00:00","url":"https://junglewise.ai/threats/cve-2026-13189-progress-telerik-ui-for-asp-net-ajax-path-traversal-in-spell"},{"cve":"CVE-2026-13188","cvss":5.9,"slug":"cve-2026-13188-progress-telerik-ui-for-asp-net-ajax-parameter-tampering-in","title":"Progress Telerik UI for ASP.NET AJAX parameter tampering in DialogHandler","severity":"medium","exploited":false,"published_at":"2026-07-22T14:17:14.417+00:00","url":"https://junglewise.ai/threats/cve-2026-13188-progress-telerik-ui-for-asp-net-ajax-parameter-tampering-in"},{"cve":"CVE-2026-13187","cvss":8.1,"slug":"cve-2026-13187-progress-telerik-ui-for-asp-net-ajax-unsafe-reflection-in","title":"Progress Telerik UI for ASP.NET AJAX unsafe reflection in DialogHandler","severity":"high","exploited":false,"published_at":"2026-07-22T14:17:14.3+00:00","url":"https://junglewise.ai/threats/cve-2026-13187-progress-telerik-ui-for-asp-net-ajax-unsafe-reflection-in"},{"cve":"CVE-2026-13186","cvss":8.1,"slug":"cve-2026-13186-progress-telerik-ui-for-asp-net-ajax-path-traversal-in","title":"Progress Telerik UI for ASP.NET AJAX path traversal in AppDataStorageProvider","severity":"high","exploited":false,"published_at":"2026-07-22T14:17:14.18+00:00","url":"https://junglewise.ai/threats/cve-2026-13186-progress-telerik-ui-for-asp-net-ajax-path-traversal-in"},{"cve":"CVE-2026-13185","cvss":8.1,"slug":"cve-2026-13185-progress-telerik-ui-for-asp-net-ajax-deserialization-in","title":"Progress Telerik UI for ASP.NET AJAX deserialization in RadPersistenceManager","severity":"high","exploited":false,"published_at":"2026-07-22T14:17:14.057+00:00","url":"https://junglewise.ai/threats/cve-2026-13185-progress-telerik-ui-for-asp-net-ajax-deserialization-in"},{"cve":"CVE-2026-9272","cvss":8.7,"slug":"cve-2026-9272-progress-flowmon-ads-sql-injection-in-anomaly-detection-system","title":"Progress Flowmon ADS SQL injection in Anomaly Detection System","severity":"info","exploited":false,"published_at":"2026-07-02T15:17:11.937+00:00","url":"https://junglewise.ai/threats/cve-2026-9272-progress-flowmon-ads-sql-injection-in-anomaly-detection-system"},{"cve":"CVE-2026-8668","cvss":2.3,"slug":"cve-2026-8668-progress-chef-360-static-credential-in-internal-message-queues","title":"Progress Chef 360 static credential in internal message queues","severity":"info","exploited":false,"published_at":"2026-06-18T22:16:32.537+00:00","url":"https://junglewise.ai/threats/cve-2026-8668-progress-chef-360-static-credential-in-internal-message-queues"},{"cve":"CVE-2026-8100","cvss":8.6,"slug":"cve-2026-8100-progress-chef-360-auth-bypass-via-url-encoded-path-traversal","title":"Progress Chef 360 auth bypass via URL-encoded path traversal","severity":"info","exploited":false,"published_at":"2026-06-18T22:16:32.353+00:00","url":"https://junglewise.ai/threats/cve-2026-8100-progress-chef-360-auth-bypass-via-url-encoded-path-traversal"},{"cve":"CVE-2026-8488","cvss":4.3,"slug":"cve-2026-8488-progress-software-moveit-automation-resource-exhaustion-in-server","title":"Progress Software MOVEit Automation resource exhaustion in Server","severity":"medium","exploited":false,"published_at":"2026-05-20T16:16:27.58+00:00","url":"https://junglewise.ai/threats/cve-2026-8488-progress-software-moveit-automation-resource-exhaustion-in-server"},{"cve":"CVE-2026-8487","cvss":6.5,"slug":"cve-2026-8487-progress-software-moveit-automation-incorrect-default-permissions","title":"Progress Software MOVEit Automation incorrect default permissions","severity":"medium","exploited":false,"published_at":"2026-05-20T16:16:27.463+00:00","url":"https://junglewise.ai/threats/cve-2026-8487-progress-software-moveit-automation-incorrect-default-permissions"},{"cve":"CVE-2026-8486","cvss":5.3,"slug":"cve-2026-8486-progress-software-moveit-automation-resource-exhaustion-via","title":"Progress Software MOVEit Automation resource exhaustion via flooding","severity":"medium","exploited":false,"published_at":"2026-05-20T16:16:27.347+00:00","url":"https://junglewise.ai/threats/cve-2026-8486-progress-software-moveit-automation-resource-exhaustion-via"},{"cve":"CVE-2026-8485","cvss":5.9,"slug":"cve-2026-8485-progress-software-moveit-automation-uncontrolled-memory-allocation","title":"Progress Software MOVEit Automation uncontrolled memory allocation","severity":"medium","exploited":false,"published_at":"2026-05-20T14:17:04.603+00:00","url":"https://junglewise.ai/threats/cve-2026-8485-progress-software-moveit-automation-uncontrolled-memory-allocation"}],"vendor":{"hub":true,"name":"Progress Software","slug":"progress-software","homepage":"https://www.progress.com/","description":"An American software company that develops tools for application development, data connectivity, and digital experience management.","url":"https://junglewise.ai/threats/vendors/progress-software"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-13190","cvss":8.1,"slug":"cve-2026-13190-progress-telerik-ui-for-asp-net-ajax-deserialization-in","title":"Progress Telerik UI for ASP.NET AJAX deserialization in PersistenceFramework","severity":"high","exploited":false,"published_at":"2026-07-22T14:17:14.667+00:00","url":"https://junglewise.ai/threats/cve-2026-13190-progress-telerik-ui-for-asp-net-ajax-deserialization-in"},{"cve":"CVE-2026-13187","cvss":8.1,"slug":"cve-2026-13187-progress-telerik-ui-for-asp-net-ajax-unsafe-reflection-in","title":"Progress Telerik UI for ASP.NET AJAX unsafe reflection in DialogHandler","severity":"high","exploited":false,"published_at":"2026-07-22T14:17:14.3+00:00","url":"https://junglewise.ai/threats/cve-2026-13187-progress-telerik-ui-for-asp-net-ajax-unsafe-reflection-in"},{"cve":"CVE-2026-13186","cvss":8.1,"slug":"cve-2026-13186-progress-telerik-ui-for-asp-net-ajax-path-traversal-in","title":"Progress Telerik UI for ASP.NET AJAX path traversal in AppDataStorageProvider","severity":"high","exploited":false,"published_at":"2026-07-22T14:17:14.18+00:00","url":"https://junglewise.ai/threats/cve-2026-13186-progress-telerik-ui-for-asp-net-ajax-path-traversal-in"},{"cve":"CVE-2026-13185","cvss":8.1,"slug":"cve-2026-13185-progress-telerik-ui-for-asp-net-ajax-deserialization-in","title":"Progress Telerik UI for ASP.NET AJAX deserialization in RadPersistenceManager","severity":"high","exploited":false,"published_at":"2026-07-22T14:17:14.057+00:00","url":"https://junglewise.ai/threats/cve-2026-13185-progress-telerik-ui-for-asp-net-ajax-deserialization-in"},{"cve":"CVE-2026-59690","cvss":8,"slug":"cve-2026-59690-progress-software-loadmaster-missing-authorization-in-rest-api","title":"Progress Software LoadMaster missing authorization in REST API","severity":"high","exploited":false,"published_at":"2026-07-27T13:18:22.457+00:00","url":"https://junglewise.ai/threats/cve-2026-59690-progress-software-loadmaster-missing-authorization-in-rest-api"},{"cve":"CVE-2026-13189","cvss":7.5,"slug":"cve-2026-13189-progress-telerik-ui-for-asp-net-ajax-path-traversal-in-spell","title":"Progress Telerik UI for ASP.NET AJAX path traversal in spell check handler","severity":"high","exploited":false,"published_at":"2026-07-22T14:17:14.537+00:00","url":"https://junglewise.ai/threats/cve-2026-13189-progress-telerik-ui-for-asp-net-ajax-path-traversal-in-spell"},{"cve":"CVE-2026-14932","cvss":6.5,"slug":"cve-2026-14932-progress-telerik-ui-for-asp-net-ajax-file-read-and-deletion-in","title":"Progress Telerik UI for ASP.NET AJAX file read and deletion in RadChart","severity":"medium","exploited":false,"published_at":"2026-07-22T14:17:15.283+00:00","url":"https://junglewise.ai/threats/cve-2026-14932-progress-telerik-ui-for-asp-net-ajax-file-read-and-deletion-in"},{"cve":"CVE-2026-13192","cvss":6.5,"slug":"cve-2026-13192-progress-telerik-ui-for-asp-net-ajax-ssrf-in-radeditor-pdf-export","title":"Progress Telerik UI for ASP.NET AJAX SSRF in RadEditor PDF export","severity":"medium","exploited":false,"published_at":"2026-07-22T14:17:14.777+00:00","url":"https://junglewise.ai/threats/cve-2026-13192-progress-telerik-ui-for-asp-net-ajax-ssrf-in-radeditor-pdf-export"},{"cve":"CVE-2026-8487","cvss":6.5,"slug":"cve-2026-8487-progress-software-moveit-automation-incorrect-default-permissions","title":"Progress Software MOVEit Automation incorrect default permissions","severity":"medium","exploited":false,"published_at":"2026-05-20T16:16:27.463+00:00","url":"https://junglewise.ai/threats/cve-2026-8487-progress-software-moveit-automation-incorrect-default-permissions"},{"cve":"CVE-2026-13188","cvss":5.9,"slug":"cve-2026-13188-progress-telerik-ui-for-asp-net-ajax-parameter-tampering-in","title":"Progress Telerik UI for ASP.NET AJAX parameter tampering in DialogHandler","severity":"medium","exploited":false,"published_at":"2026-07-22T14:17:14.417+00:00","url":"https://junglewise.ai/threats/cve-2026-13188-progress-telerik-ui-for-asp-net-ajax-parameter-tampering-in"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Progress Software UI for ASP.NET AJAX","slug":"ui-for-asp-net-ajax","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/ui-for-asp-net-ajax"},{"name":"Progress Software MOVEit Automation","slug":"moveit-automation","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/moveit-automation"}]}