# Progress Software vulnerabilities & exploitation

**CISA KEV**

> As of 2026-10-10, Threadlinqs tracks 9 Progress Software CVEs, 2 in the CISA Known Exploited Vulnerabilities catalog, linked to 13 tracked threat campaigns and 3 named threat actors.

**Data as of:** 2026-10-10

## Exploitation timeline

Threadlinqs has recorded 9 Progress Software CVEs published between 2024-02-15 and 2026-10-15. The busiest month was 2026-07 (4 new CVEs). 2 of them (22%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 9 of 9 tracked Progress Software CVEs.

- [CVE-2024-1212](https://intel.threadlinqs.com/cve/CVE-2024-1212) — CRITICAL 10 · KEV · EPSS 95.4% · 2024-02-21
- [CVE-2026-8037](https://intel.threadlinqs.com/cve/CVE-2026-8037) — CRITICAL 9.6 · KEV · EPSS 77.4% · 2026-06-04
- [CVE-2026-91140](https://intel.threadlinqs.com/cve/CVE-2026-91140) — CRITICAL 9.6 · EPSS 1.9% · 2026-10-06
- [CVE-2026-4670](https://intel.threadlinqs.com/cve/CVE-2026-4670) — CRITICAL 9.8 · EPSS 0.6% · 2026-04-30
- [CVE-2026-13181](https://intel.threadlinqs.com/cve/CVE-2026-13181) — HIGH 8.1 · EPSS 0.5% · 2026-07-22
- [CVE-2026-5174](https://intel.threadlinqs.com/cve/CVE-2026-5174) — HIGH 7.7 · EPSS 0.5% · 2026-04-30
- [CVE-2026-13183](https://intel.threadlinqs.com/cve/CVE-2026-13183) — HIGH 7.5 · EPSS 0.4% · 2026-07-22
- [CVE-2026-13182](https://intel.threadlinqs.com/cve/CVE-2026-13182) — HIGH 7.5 · EPSS 0.3% · 2026-07-22
- [CVE-2026-13184](https://intel.threadlinqs.com/cve/CVE-2026-13184) — HIGH 7.5 · EPSS 0.3% · 2026-07-22

## Products affected

Threadlinqs normalises CPE and CNA product records across all 9 CVEs; 7 distinct Progress Software products are affected. The most frequently affected:

- Telerik UI for ASP.NET AJAX — 4 CVEs
- LoadMaster — 2 CVEs
- MOVEit Automation — 2 CVEs
- Autonomous REST Connector GenAI Agents — 1 CVE
- ECS Connections Manager — 1 CVE
- MOVEit WAF — 1 CVE
- Object Scale Connection Manager — 1 CVE

## Threat activity

13 tracked threat campaigns reference Progress Software products or exploit Progress Software CVEs:

- [Progress DataDirect GenAI Command Injection via OpenAPI/Swagger Filename (CVE-2026-91140)](https://intel.threadlinqs.com/threat/TL-2026-3226) — CRITICAL — 2026-10-10
- [Cl0p Ransomware MFT Attack Pattern: Multi-Year Zero-Day Campaigns Against File Transfer and Enterprise Software (2020-2025)](https://intel.threadlinqs.com/threat/TL-2026-3070) — HIGH — 2026-10-09
- [CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS Servers](https://intel.threadlinqs.com/threat/TL-2026-2726) — CRITICAL — 2026-09-28
- [Telerik UI for ASP.NET AJAX — Padding Oracle Chained to Unauthenticated Deserialization RCE (CVE-2026-13181–13184)](https://intel.threadlinqs.com/threat/TL-2026-2369) — HIGH — 2026-09-07
- [Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web servers](https://intel.threadlinqs.com/threat/TL-2026-2096) — HIGH — 2026-08-21
- [Progress ShareFile Zero-Day Path Traversal Flaw Forces Storage Zone Controller Shutdown](https://intel.threadlinqs.com/threat/TL-2026-1317) — HIGH — 2026-07-14
- [CVE-2026-8037: Pre-Authentication Remote Code Execution in Progress Kemp LoadMaster via escape_quotes() Heap Out-of-Bounds Read](https://intel.threadlinqs.com/threat/TL-2026-1132) — CRITICAL — 2026-07-05
- [CVE-2026-8037: Unauthenticated OS Command Injection in Progress Kemp LoadMaster via Uninitialized Heap in escape_quotes() (CVSS 9.6-9.8, Active Exploitation)](https://intel.threadlinqs.com/threat/TL-2026-1067) — CRITICAL — 2026-07-02
- [CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap escape_quotes() Flaw on /accessv2](https://intel.threadlinqs.com/threat/TL-2026-1045) — CRITICAL — 2026-07-01
- [Progress MOVEit Automation Critical Pre-Auth Bypass and Privilege Escalation (CVE-2026-4670, CVE-2026-5174)](https://intel.threadlinqs.com/threat/TL-2026-0452) — CRITICAL — 2026-05-04
- [APT35 (Charming Kitten) GCC Pre-Positioning Cyber Reconnaissance Campaign Enabling Kinetic Targeting](https://intel.threadlinqs.com/threat/TL-2026-0339) — CRITICAL — 2026-04-09
- [Progress ShareFile Pre-Auth RCE Chain via Authentication Bypass and Webshell Upload (CVE-2026-2699 & CVE-2026-2701)](https://intel.threadlinqs.com/threat/TL-2026-0317) — CRITICAL — 2026-04-04
- [Progress ShareFile Pre-Auth RCE Chain via Auth Bypass (CVE-2026-2699, CVE-2026-2701)](https://intel.threadlinqs.com/threat/TL-2026-1513) — CRITICAL — 2026-04-02

## Threat actors targeting Progress Software

Named threat actors attributed to campaigns that involve Progress Software products or CVEs, with the number of linked campaigns:

- [APT35](https://intel.threadlinqs.com/actor/APT35) — 1 campaign
- [APT42](https://intel.threadlinqs.com/actor/APT42) — 1 campaign
- [Cl0p](https://intel.threadlinqs.com/actor/Cl0p) — 1 campaign

## How to prioritise Progress Software patching

This order follows the data Threadlinqs holds for Progress Software, not a generic severity checklist:

- 2 of 9 Progress Software CVEs (22%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2024-1212](https://intel.threadlinqs.com/cve/CVE-2024-1212), [CVE-2026-8037](https://intel.threadlinqs.com/cve/CVE-2026-8037).
- Outside KEV, the highest EPSS scores are [CVE-2026-91140](https://intel.threadlinqs.com/cve/CVE-2026-91140) (1.9%), [CVE-2026-4670](https://intel.threadlinqs.com/cve/CVE-2026-4670) (0.6%), [CVE-2026-13181](https://intel.threadlinqs.com/cve/CVE-2026-13181) (0.5%).
- 4 CVEs score Critical and 5 High on CVSS v3 (maximum 10, average 8.6); sequence these after KEV and high-EPSS items.
- 3 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-10 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/progress-software
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
