SecAlerts
Progress logo

Progress

Security Risk Profile

61
/100
high

Security Risk Score

Comprehensive risk assessment based on 301 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 2, 1999 to present

301
Total CVEs
226
Critical+High
13
Exploited
204
Unpatched

Threat Assessment

Avg CVSS
7.9
Base severity
Avg EPSS
3%
Exploit probability
Unpatched
204
Critical/High
Risk Level
61/100
high
⚠️ 13 Active Exploits 9 Zero-Days🆕 5Fresh (<7d)📈 30 in Last 30 Days

Severity Distribution

Critical
65
High
161
Medium
64
Low
0

Exploit Likelihood

>50% chance
2
20-50%
0
5-20%
1
<5%
69

Age Distribution

Common Weaknesses (CWE)

1
XSS
41
2
SQL Injection
28
3
Command Injection
27
4
OS Command Injection
26
5
Path Traversal
19

Most Affected Products

1. Progress MOVEit Transfer155
2. Progress Sitefinity112
3. Progress Ws Ftp Server90
4. Progress LoadMaster75
5. Progress WhatsUp Gold74

Recent Vulnerabilities

See more →
CVE-2026-59690
CVSS 8.0high

Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API

7/27/2026🔧 No Patch
CVE-2026-59689
CVSS 8.0high

Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root

7/27/2026🔧 No Patch
CVE-2026-59688
CVSS 8.4high

Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality

7/27/2026🔧 No Patch
CVE-2026-59687
CVSS 8.4high

Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface

7/27/2026🔧 No Patch
CVE-2026-59686
CVSS 8.4high

Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface

7/27/2026🔧 No Patch
CVE-2026-15968
CVSS 7.1high

Stored XSS vulnerability in MOVEit Transfer

7/23/2026🔧 No Patch
CVE-2026-15967
CVSS 9.8critical

MOVEit Transfer refresh-token processing does not enforce updated account restrictions

7/23/2026🔧 No Patch
CVE-2026-15966
CVSS 9.8critical

Improper CORS handling in MOVEit Transfer

7/23/2026🔧 No Patch
CVE-2026-10697
CVSS 9.8critical

MFA Bypass in MOVEit Transfer

7/23/2026🔧 No Patch
CVE-2026-14932
CVSS 6.5medium

Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart

7/22/2026🔧 No Patch

Monitor Progress in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Progress Security Vulnerabilities & Risk Score | 301 CVEs | SecAlerts - SecAlerts