Progress threat watch

Progress CVE coverage for MOVEit, Telerik, OpenEdge, and high-impact enterprise file-transfer or application platforms.

Watch items

Recent Progress watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows · sorted newest first

Operations view

moveit transfer vulnerability (CVE-2026-8801)

CRITICAL
watchNVDCVE-2026-8801

Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.

Jul 8, 2026, 3:17 PMOfficial source

moveit transfer vulnerability (CVE-2026-8800)

HIGH
watchNVDCVE-2026-8800

Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Jul 8, 2026, 3:17 PMOfficial source

moveit transfer vulnerability (CVE-2026-8651)

HIGH
watchNVDCVE-2026-8651

Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Jul 8, 2026, 3:17 PMOfficial source

moveit transfer vulnerability (CVE-2026-8650)

HIGH
watchNVDCVE-2026-8650

Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Jul 8, 2026, 3:17 PMOfficial source

moveit transfer vulnerability (CVE-2026-8649)

CRITICAL
watchNVDCVE-2026-8649

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Jul 8, 2026, 3:17 PMOfficial source

flowmon anomaly detection system vulnerability (CVE-2026-9272)

HIGH
watchNVDCVE-2026-9272

In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification.

Jul 2, 2026, 10:17 AMOfficial source

flowmon vulnerability (CVE-2026-8079)

HIGH
watchNVDCVE-2026-8079

In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.

Jul 2, 2026, 10:17 AMOfficial source

connection manager for objectscale vulnerability (CVE-2026-8037)

CRITICAL
watchNVDCVE-2026-8037

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Jun 4, 2026, 9:16 AMOfficial source

sitefinity vulnerability (CVE-2026-7312)

HIGH
watchNVDCVE-2026-7312

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, and 15.4.8600 to 15.4.8630 allows a remote unauthenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight and non-default site configuration.

Jun 2, 2026, 9:17 AMOfficial source

sitefinity vulnerability (CVE-2026-7195)

HIGH
watchNVDCVE-2026-7195

CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote unauthenticated attacker to compromise the integrity and confidentiality of user accounts. Successful exploitation requires user interaction and a non-default site configuration.

Jun 2, 2026, 9:17 AMOfficial source

moveit automation vulnerability (CVE-2026-8488)

HIGH
watchNVDCVE-2026-8488

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

May 20, 2026, 11:16 AMOfficial source

moveit automation vulnerability (CVE-2026-8487)

HIGH
watchNVDCVE-2026-8487

Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

May 20, 2026, 11:16 AMOfficial source

moveit automation vulnerability (CVE-2026-8486)

HIGH
watchNVDCVE-2026-8486

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

May 20, 2026, 11:16 AMOfficial source

moveit automation vulnerability (CVE-2026-8485)

HIGH
watchNVDCVE-2026-8485

Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

May 20, 2026, 9:17 AMOfficial source

moveit automation vulnerability (CVE-2026-5174)

HIGH
watchNVDCVE-2026-5174

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

Apr 30, 2026, 11:16 AMOfficial source

telerik ui for asp.net ajax vulnerability (CVE-2026-6023)

CRITICAL
watchNVDCVE-2026-6023

In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.

Apr 22, 2026, 3:16 AMOfficial source

connection manager for objectscale vulnerability (CVE-2026-4048)

HIGH
watchNVDCVE-2026-4048

OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.

Apr 20, 2026, 9:16 AMOfficial source

connection manager for objectscale vulnerability (CVE-2026-3519)

HIGH
watchNVDCVE-2026-3519

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command

Apr 20, 2026, 9:16 AMOfficial source

connection manager for objectscale vulnerability (CVE-2026-3518)

HIGH
watchNVDCVE-2026-3518

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command

Apr 20, 2026, 9:16 AMOfficial source

connection manager for objectscale vulnerability (CVE-2026-3517)

HIGH
watchNVDCVE-2026-3517

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command

Apr 20, 2026, 9:16 AMOfficial source

Vendor watch hub

What this page covers

The Progresswatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent Progress activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

37

Active

9

Featured

15

Unique CVEs

20

Most recent entry

Jul 8, 2026, 3:17 PM

Feed refreshes daily · 5:15 a.m. Central

Sources·CISA KEV and NVD (product vendor coverage)

"Most recent entry" is the newest item the upstream feed has published — not our sync time.

Related vendors

Other productivity vendors in the radar

Vendor watch FAQ

Common questions

What is the Progress threat watch page?

It is the Progress-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the Progress watch page?

Use it to confirm whether current Progress issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to Progress security issues?

Yes. ITECS can help map Progress advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.