Progress vulnerabilities
22 CVEs tracked
Progress is currently in the spotlight due to both a real-world security incident and critical vulnerabilities. The company restored access to its ShareFile Storage Zones Controller after a four-day suspension caused by a credible external threat. Concurrently, 8 new CVEs were revealed for the Telerik UI for AJAX product, notably CVE-2026-13185 and CVE-2026-13181, which enable unauthenticated remote code execution (RCE). Defenders must immediately patch Telerik UI for AJAX to v2026.2.708 or later, while also revisiting CVE-2026-10697 related to MOVEit Transfer to mitigate potential authentication bypass.
Azərbaycanca: Progress vendoru, son hesabatlarda həm real təhlükəsizlik insidenti, həm də kritik zəifliklər ilə diqqət mərkəzindədir. Şirkət, kənar təhlükə səbəbindən ShareFile Storage Zones Controller girişini 4 günlük dayandırdıqdan sonra bərpa edib. Paralel olaraq, Telerik UI for AJAX məhsulunda 8 yeni CVE aşkarlanıb ki, bunlardan CVE-2026-13185 və CVE-2026-13181 autentifikasiya olunmadan uzaqdan kod icrasına (RCE) imkan verir. Müdafiəçilər dərhal Telerik UI for AJAX-ı v2026.2.708 və ya daha yeni versiyaya yeniləməli, eyni zamanda MOVEit Transfer üçün CVE-2026-10697 ilə bağlı əvvəlki xəbərdarlığı nəzərə almalıdır.
This vendor's CVEs22
- CVE-2026-64849KEVEPSS 16%
- CVE-2026-8037KEVEPSS 100%
- CVE-2026-16139EPSS 0.65%
- CVE-2026-16138EPSS 0.26%
- CVE-2026-15968EPSS 0.18%
- CVE-2026-15967EPSS 0.20%
- CVE-2026-15966EPSS 0.20%
- CVE-2026-14932EPSS 0.35%
- CVE-2026-14865EPSS 0.43%
- CVE-2026-13192EPSS 0.24%
- CVE-2026-13190EPSS 0.67%
- CVE-2026-13189EPSS 0.54%
- CVE-2026-13188EPSS 0.16%
- CVE-2026-13187EPSS 0.47%
- CVE-2026-13186EPSS 0.53%
- CVE-2026-13185EPSS 0.49%
- CVE-2026-13184EPSS 0.35%
- CVE-2026-13183EPSS 0.54%
- CVE-2026-13182EPSS 0.54%
- CVE-2026-13181EPSS 0.67%
- CVE-2026-10697EPSS 0.29%
- CVE-2026-7326EPSS 0.14%
This hub is built from skopnix's own reporting on Progress: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.