In Progress Flowmon ADS versions prior to 12
Description
In Progress Flowmon ADS versions prior to 12
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
19 vulnerabilities from Progress
← Back to all CVEsIn Progress Flowmon ADS versions prior to 12
In Progress Flowmon ADS versions prior to 12
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In Progress Flowmon versions prior to 12
In Progress Flowmon versions prior to 12
---METADATA---
VENDOR: Progress
PRODUCT: Flowmon
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
A critical vulnerability exists in Progress Flowmon versions prior to 12, potentially exposing the system to unauthorized access or compromise.
Executive Summary:
Progress Flowmon versions prior to 12 contain a high-severity vulnerability that could lead to unauthorized system access or service disruption.
Vulnerability Details
CVE-ID: CVE-2026-8079
Affected Software: Progress Flowmon
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This vulnerability affects Progress Flowmon software and is categorized as a high-severity issue; specific technical details regarding the authentication level are pending further vendor disclosure.
Business Impact
The CVSS score of 8.7 highlights the significant threat to infrastructure monitoring operations. Exploitation could lead to the exposure of sensitive network traffic metadata or the compromise of monitoring integrity, resulting in severe operational downtime or data exfiltration.
Remediation Plan
Immediate Action: Upgrade all instances of Progress Flowmon to version 12 or higher as mandated by the vendor's security guidance.
Proactive Monitoring: Monitor system logs for unauthorized access attempts or unusual traffic patterns directed at the Flowmon management interface.
Compensating Controls: Restrict access to the Flowmon management interface to trusted IP ranges via firewall rules until the patch can be verified and applied.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 3, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Security teams should treat this vulnerability with high urgency and move to upgrade the affected Flowmon deployments immediately. Ensuring the transition to version 12 is critical to mitigating the risk of unauthorized access to network monitoring infrastructure.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands...
Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands on the underlying system.
---METADATA---
VENDOR: Progress
PRODUCT: LoadMaster
AFFECTED_VERSIONS: Progress Software LoadMaster: V7.2.60.0 up to (excluding) V7.2.63.2, V7.2.45.12 up to (excluding) V7.2.54.18; ECS Connections Manager: V7.2.60.0 up to (excluding) V7.2.63.2; Object Scale Connection Manager: V7.2.60.0 up to (excluding) V7.2.63.2; MOVEit WAF: V7.2.60.0 up to (excluding) V7.2.63.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands on the underlying system.
Executive Summary:
A critical command injection vulnerability in Progress LoadMaster is currently being exploited in the wild, posing a severe risk of total system compromise.
Vulnerability Details
CVE-ID: CVE-2026-8037
Affected Software: Progress LoadMaster, ECS Connections Manager, Object Scale Connection Manager, and MOVEit WAF
Affected Versions: See metadata for specific version ranges.
Vulnerability: This vulnerability is a command injection flaw (CWE-77) occurring in the management interfaces of the affected software. It allows an unauthenticated attacker to inject and execute arbitrary operating system commands with high privileges.
Business Impact
Successful exploitation results in full control over the affected appliance, leading to unauthorized access to sensitive data, potential lateral movement within the network, and complete service disruption. Given the CVSS score of 9.5 and confirmed active exploitation, organizations face an extreme risk of data exfiltration and operational downtime.
Remediation Plan
Immediate Action: Apply the vendor-provided security updates immediately to address the vulnerability. If immediate patching is not possible, follow the specific mitigation instructions provided in the official Progress security bulletin.
Proactive Monitoring: Review system logs for unusual process execution or unauthorized command-line activity originating from the load balancer. Monitor network traffic for suspicious patterns directed at management interfaces.
Compensating Controls: Restrict access to the management interface of the LoadMaster appliance to known, trusted administrative IP addresses using firewall rules or ACLs to reduce the attack surface.
Exploitation Status
Public Exploit Available: Yes, a Nuclei detection template exists.
Analyst Notes: This vulnerability is confirmed to be actively exploited in the wild as of August 7, 2026. While weaponized exploit code is not currently confirmed in public repositories, the active exploitation and availability of detection templates necessitate immediate remediation.
Analyst Recommendation
The combination of a 9.5 severity score and active exploitation in the wild makes this a top-priority security event. Administrators must prioritize the application of vendor patches or documented mitigations to prevent unauthorized system access and potential data loss.
Actively exploited in the wild (CISA KEV). Apply vendor updates or mitigations promptly.
Deadline: August 10, 2026
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11
An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11
---METADATA---
VENDOR: Progress
PRODUCT: MarkLogic Server
AFFECTED_VERSIONS: 11.0.0 up to 11.3.6, 12.0.0 up to 12.0.3
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
An improper privilege management vulnerability in the REST API document processing pipeline of MarkLogic Server allows authenticated users to escalate privileges.
Executive Summary:
MarkLogic Server contains an improper privilege management vulnerability that allows an authenticated user to perform unauthorized actions within the document processing pipeline.
Vulnerability Details
CVE-ID: CVE-2026-7327
Affected Software: Progress MarkLogic Server
Affected Versions: 11.0.0 up to 11.3.6, and 12.0.0 up to 12.0.3
Vulnerability: This is an improper privilege management vulnerability (CWE-269) within the REST API document processing pipeline. It requires the attacker to have high privileges (authenticated) to successfully exploit the flaw.
Business Impact
Successful exploitation allows an authenticated user to perform actions beyond their authorized scope, potentially leading to unauthorized data access or modification within the document processing pipeline. Given the CVSS score of 8.1, this represents a significant threat to data integrity and confidentiality, especially in environments where strict role-based access control is required.
Remediation Plan
Immediate Action: Apply the latest security updates provided by Progress Software Corporation to upgrade to a non-vulnerable version (11.3.6 or 12.0.3 or higher).
Proactive Monitoring: Review access logs and audit trails for unauthorized attempts to access or modify documents via the REST API, particularly by users with restricted roles.
Compensating Controls: Limit access to the REST API endpoints to known, trusted IP addresses and enforce the principle of least privilege for all user accounts interacting with the database.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of August 6, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. Per CISA's SSVC assessment, there is no confirmed active exploitation, and the vulnerability is not considered automatable.
Analyst Recommendation
While this vulnerability requires prior authentication, the potential for privilege escalation within a database environment remains a high-risk scenario. Organizations should prioritize updating their MarkLogic instances to the specified patched versions to ensure robust access control and maintain the security posture of their data.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8
---METADATA---
VENDOR: Progress
PRODUCT: Sitefinity
AFFECTED_VERSIONS: Progress Sitefinity version from 8.0.5700 to 13.3.7652
---END_METADATA---
Description Summary:
Progress Sitefinity versions 8.0.5700 through 13.3.7652 contain a vulnerability allowing remote authenticated attackers to obtain plain-text credentials for the Sitefinity Insight service.
Executive Summary:
A high-severity credential exposure vulnerability in Progress Sitefinity allows authenticated attackers to access sensitive credentials used for integration with the Sitefinity Insight service.
Vulnerability Details
CVE-ID: CVE-2026-7313
Affected Software: Progress Sitefinity
Affected Versions: Progress Sitefinity version from 8.0.5700 to 13.3.7652
Vulnerability: This is an "Insufficiently Protected Credentials" (CWE-522) vulnerability within web services. Exploitation requires a remote authenticated attacker with valid back-end authorization, non-default site configuration, and an active integration with the Sitefinity Insight service.
Business Impact
With a CVSS score of 8.7, this flaw poses a severe risk of data compromise. By obtaining plain-text credentials for the Sitefinity Insight service, an attacker could gain unauthorized access to secondary systems, potentially leading to further data breaches or service manipulation.
Remediation Plan
Immediate Action: Update Progress Sitefinity to a patched version beyond 13.3.7652 immediately.
Proactive Monitoring: Monitor access logs for unusual administrative activity and audit all integrations configured with the Sitefinity Insight service.
Compensating Controls: Rotate all credentials associated with the Sitefinity Insight service after applying the patch to ensure any previously exposed secrets are invalidated.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of June 4, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Organizations running affected versions of Sitefinity should treat this as a high-priority update. Because the vulnerability involves credential exposure, simply patching is insufficient; administrators must also rotate credentials to ensure full remediation.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Progress Sitefinity web services contain a vulnerability that allows unauthenticated remote attackers to retrieve plain-text credentials for the Sitef...
Progress Sitefinity web services contain a vulnerability that allows unauthenticated remote attackers to retrieve plain-text credentials for the Sitefinity Insight service.
---METADATA---
VENDOR: Progress
PRODUCT: Sitefinity
AFFECTED_VERSIONS: 14.0.7700 to 14.4.8152, 15.0.8200 to 15.0.8234, 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, 15.4.8600 to 15.4.8630
---END_METADATA---
Description Summary:
Progress Sitefinity web services contain a vulnerability that allows unauthenticated remote attackers to retrieve plain-text credentials for the Sitefinity Insight service.
Executive Summary:
A critical credential disclosure vulnerability in Progress Sitefinity allows unauthenticated remote attackers to obtain sensitive plain-text credentials for integrated services.
Vulnerability Details
CVE-ID: CVE-2026-7312
Affected Software: Progress Sitefinity
Affected Versions: 14.0.7700 to 14.4.8152, 15.0.8200 to 15.0.8234, 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, 15.4.8600 to 15.4.8630
Vulnerability: The web services component fails to protect credentials, allowing an unauthenticated attacker to access plain-text credentials used for the Sitefinity Insight service, provided the installation has active integration and non-default configurations.
Business Impact
The exposure of plain-text credentials poses a significant risk of unauthorized access to the Sitefinity Insight service, potentially resulting in data exfiltration or manipulation of business analytics. Although the CVSS score is 10.0, the requirement for non-default site configurations acts as a limiting factor, though the impact remains severe for affected enterprise environments.
Remediation Plan
Immediate Action: Apply the vendor-provided patch corresponding to your specific version (e.g., 14.4.8152, 15.0.8234, etc.) immediately.
Proactive Monitoring: Review access logs for anomalous requests to web services and perform a credential rotation for all services integrated with Sitefinity Insight following the patch.
Compensating Controls: Ensure the Sitefinity instance is behind a robust WAF and restrict external access to web service endpoints that are not required for public operation.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Jun 2, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Given the perfect CVSS score, this vulnerability demands immediate attention. Administrators must identify their current version and apply the specified patch to prevent the exposure of sensitive service credentials.
Update Progress Sitefinity version to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15
---METADATA---
VENDOR: Progress
PRODUCT: Sitefinity
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
An authorization bypass vulnerability via user-controlled keys in web services affects Progress Sitefinity 15.
Executive Summary:
Progress Sitefinity 15 is vulnerable to an authorization bypass flaw that allows attackers to manipulate user-controlled keys to gain unauthorized access.
Vulnerability Details
CVE-ID: CVE-2026-7201
Affected Software: Progress Sitefinity
Affected Versions: See vendor advisory for specific affected versions.
Vulnerability: This vulnerability (CWE-639) occurs in the web services layer, where the application fails to properly validate the relationship between a user's session and the requested resource key, allowing for unauthorized access.
Business Impact
The CVSS score of 8.8 highlights the high severity of this flaw. An attacker could potentially access or modify data they are not authorized to view, leading to a loss of confidentiality and integrity within the Sitefinity platform.
Remediation Plan
Immediate Action: Apply the latest security patches provided by Progress for Sitefinity 15 to remediate the authorization logic error.
Proactive Monitoring: Review application logs for unauthorized attempts to access resources using altered or manipulated identifiers.
Compensating Controls: Implement robust session management and ensure that all API endpoints enforce strict authorization checks independent of client-provided keys.
Exploitation Status
Public Exploit Available: False
Analyst Notes: As of June 3, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Authorization bypass vulnerabilities are critical as they often lead to direct data exposure. It is imperative that administrators apply the relevant security updates for Sitefinity 15 immediately to prevent potential exploitation.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Improper access control in Progress Sitefinity web services allows unauthenticated attackers to access restricted content and fully compromise the ins...
Improper access control in Progress Sitefinity web services allows unauthenticated attackers to access restricted content and fully compromise the installation.
---METADATA---
VENDOR: Progress
PRODUCT: Sitefinity
AFFECTED_VERSIONS: 15.4.8623 before 15.4.8630
---END_METADATA---
Description Summary:
Improper access control in Progress Sitefinity web services allows unauthenticated attackers to access restricted content and fully compromise the installation.
Executive Summary:
A critical access control vulnerability in Progress Sitefinity allows unauthenticated attackers to gain full control over the confidentiality, integrity, and availability of the system.
Vulnerability Details
CVE-ID: CVE-2026-7198
Affected Software: Progress Sitefinity
Affected Versions: 15.4.8623 before 15.4.8630
Vulnerability: This is an improper access control vulnerability within the web services layer, permitting an unauthenticated attacker to bypass authorization checks and access sensitive, restricted content.
Business Impact
This flaw allows for a total compromise of the affected Sitefinity installation, which can lead to data breaches, unauthorized modification of web content, and complete loss of system availability. With a CVSS score of 9.8, this represents an extreme risk to any organization relying on Sitefinity for external-facing web presence.
Remediation Plan
Immediate Action: Update Sitefinity to version 15.4.8630 or later to remediate the access control bypass.
Proactive Monitoring: Monitor web access logs for unauthorized attempts to access restricted directories or administrative endpoints.
Compensating Controls: Temporarily restrict access to web services via IP whitelisting or WAF rules if immediate patching is not feasible.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Jun 2, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
The severity of this vulnerability necessitates an immediate update. Organizations should verify their current version against the affected range and apply the 15.4.8630 patch as a matter of urgency.
Update Progress Sitefinity to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
CWE-20: Improper Input Validation in web services in Progress Sitefinity 14
CWE-20: Improper Input Validation in web services in Progress Sitefinity 14
---METADATA---
VENDOR: Progress
PRODUCT: Sitefinity
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
Improper input validation in web services within Progress Sitefinity 14 may lead to security vulnerabilities.
Executive Summary:
Progress Sitefinity 14 is susceptible to an improper input validation vulnerability within its web services, posing a risk of unauthorized interaction.
Vulnerability Details
CVE-ID: CVE-2026-7195
Affected Software: Progress Sitefinity
Affected Versions: See vendor advisory for specific affected versions.
Vulnerability: The vulnerability stems from improper input validation (CWE-20) in the web services layer. An attacker may be able to provide specially crafted inputs to these services to bypass expected processing logic.
Business Impact
With a CVSS score of 8.8, this vulnerability represents a significant security risk. Successful exploitation could lead to unauthorized data manipulation or service disruption, potentially compromising the integrity of the Sitefinity content management system and the data it hosts.
Remediation Plan
Immediate Action: Update to the latest version of Progress Sitefinity as specified by the vendor’s security advisory to ensure the input validation flaws are corrected.
Proactive Monitoring: Monitor web service traffic for anomalous input payloads that deviate from expected API call structures.
Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets designed to detect and block common input validation attack patterns.
Exploitation Status
Public Exploit Available: False
Analyst Notes: As of June 3, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Security teams should prioritize patching Progress Sitefinity instances. Given the high CVSS score, immediate application of vendor-supplied security updates is strongly recommended to protect against potential exploitation of the web services.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or reke...
Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, occupying the single in-progress operation slot
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
An authentication bypass vulnerability in Progress Software MOVEit Automation allows unauthorized access to the application.
An authentication bypass vulnerability in Progress Software MOVEit Automation allows unauthorized access to the application.
---METADATA---
VENDOR: Progress Software
PRODUCT: MOVEit Automation
AFFECTED_VERSIONS: 2025.0.0-2025.0.8, 2024.0.0-2024.1.7, prior to 2024.0.0
---END_METADATA---
Description Summary:
An authentication bypass vulnerability in Progress Software MOVEit Automation allows unauthorized access to the application.
Executive Summary:
A critical authentication bypass vulnerability in Progress Software MOVEit Automation allows attackers to circumvent login requirements and gain unauthorized access.
Vulnerability Details
CVE-ID: CVE-2026-4670
Affected Software: Progress Software MOVEit Automation
Affected Versions: 2025.0.0 before 2025.0.9, 2024.0.0 before 2024.1.8, and versions prior to 2024.0.0.
Vulnerability: The application contains a flaw that permits an authentication bypass, effectively allowing an attacker to access the system without valid credentials.
Business Impact
With a CVSS score of 9.8, this vulnerability is critical. Unauthorized access to MOVEit Automation, which is frequently used for sensitive file transfers, poses an extreme risk of data exfiltration and loss of confidentiality for all data processed by the platform.
Remediation Plan
Immediate Action: Update MOVEit Automation to the latest patched version (2025.0.9, 2024.1.8, or the latest available) immediately.
Proactive Monitoring: Review authentication and access logs for anomalous login activity or unauthorized access attempts from unexpected IP addresses.
Compensating Controls: Implement strict network access controls to limit access to the MOVEit interface to known, trusted management segments.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of April 30, 2026, there is no public information indicating active exploitation. However, the criticality of authentication bypasses requires immediate attention.
Analyst Recommendation
Organizations should prioritize this update. Given the nature of MOVEit as a high-value target for data theft, ensure that the patch is applied across all instances immediately.
Update Progress Software MOVEit to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
A path traversal vulnerability in Budibase's PWA ZIP processing allows authenticated builders to exfiltrate sensitive server files, including environm...
A path traversal vulnerability in Budibase's PWA ZIP processing allows authenticated builders to exfiltrate sensitive server files, including environment variables and encryption keys.
---METADATA---
VENDOR: Budibase
PRODUCT: Budibase (PWA Component)
AFFECTED_VERSIONS: 3.31.5 and earlier
---END_METADATA---
Description Summary:
A path traversal vulnerability in Budibase's PWA ZIP processing allows authenticated builders to exfiltrate sensitive server files, including environment variables and encryption keys.
Executive Summary:
Authenticated users with builder privileges can completely compromise the Budibase platform by using a path traversal flaw to steal cryptographic secrets and service credentials.
Vulnerability Details
CVE-ID: CVE-2026-30240
Affected Software: Budibase
Affected Versions: 3.31.5 and earlier
Vulnerability: A path traversal flaw exists in the POST /api/pwa/process-zip endpoint. By crafting a malicious icons.json file inside a ZIP upload, an authenticated builder can force the server to read arbitrary files like /proc/1/environ and upload them to public-facing object storage.
Business Impact
This vulnerability leads to a total platform compromise. By exfiltrating environment variables, an attacker gains access to JWT secrets, database credentials, and API tokens. The CVSS score of 9.6 is justified because the flaw allows a user with limited "builder" permissions to elevate their access to a full system administrator and compromise the underlying infrastructure.
Remediation Plan
Immediate Action: Update Budibase to the latest version (post-3.31.5) which includes sanitized path joining and input validation for the PWA processing endpoint.
Proactive Monitoring: Monitor MinIO or S3 object stores for unexpected file uploads, and review builder activity logs for suspicious ZIP processing requests.
Compensating Controls: Implement the principle of least privilege by restricting builder access to trusted personnel and rotate all secrets (JWT, DB, API keys) if exploitation is suspected.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of March 9, 2026, there is no public information indicating active exploitation. The severity is exceptionally high because it facilitates the mass exfiltration of all service credentials in a single request.
Analyst Recommendation
The ability to exfiltrate the server's environment variables is a "game-over" scenario for any application. Organizations using Budibase must update their installations immediately and consider rotating all platform secrets as a precautionary measure.
Update Progress Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
In Progress ShareFile Storage Zones Controller v5
In Progress ShareFile Storage Zones Controller v5
---METADATA---
VENDOR: Progress
PRODUCT: ShareFile Storage Zones Controller
AFFECTED_VERSIONS: 0 through 5.12.5
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Progress ShareFile Storage Zones Controller contains a deserialization of untrusted data vulnerability that could lead to unauthorized system impact.
Executive Summary:
A deserialization vulnerability in Progress ShareFile Storage Zones Controller exposes systems to potential compromise through the processing of untrusted data.
Vulnerability Details
CVE-ID: CVE-2026-16138
Affected Software: Progress ShareFile Storage Zones Controller
Affected Versions: 0 through 5.12.5
Vulnerability: This vulnerability is a deserialization of untrusted data (CWE-502) flaw. The attack vector requires the attacker to have low privileges on an adjacent network, where they can exploit the controller to achieve high impact on confidentiality, integrity, and availability.
Business Impact
Successful exploitation allows an attacker to execute arbitrary code or perform unauthorized actions within the context of the Storage Zones Controller. Given the CVSS score of 8.0, this represents a high risk to business operations, potentially leading to total system compromise and the exposure of sensitive data stored within the ShareFile environment.
Remediation Plan
Immediate Action: Upgrade to ShareFile Storage Zones Controller version 5.12.6 or later to eliminate the vulnerable deserialization code path.
Proactive Monitoring: Inspect network traffic for unusual patterns directed at the Storage Zones Controller and review administrative access logs for unauthorized activity.
Compensating Controls: Implement network segmentation to restrict access to the controller to authorized personnel only, reducing the attack surface for adjacent network threats.
Exploitation Status
Public Exploit Available: No confirmed public exploit available.
Analyst Notes: As of August 18, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. Deserialization flaws are inherently dangerous and often facilitate remote code execution, necessitating prompt remediation.
Analyst Recommendation
The vulnerability poses a significant risk to the integrity of the ShareFile infrastructure. Administrators should prioritize the deployment of version 5.12.6, as patching is the only effective method to remediate this deserialization flaw.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In Progress® Telerik® UI for AJAX prior to v2026
In Progress® Telerik® UI for AJAX prior to v2026
---METADATA---
VENDOR: Progress
PRODUCT: Telerik UI for ASP.NET AJAX
AFFECTED_VERSIONS: 2011.2.712 up to (excluding) 2026.2.708
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
An unsafe deserialization vulnerability in Progress Telerik UI for ASP.NET AJAX allows unauthenticated attackers to execute arbitrary code via malicious serialized objects.
Executive Summary:
A critical deserialization vulnerability in Progress Telerik UI for ASP.NET AJAX enables unauthenticated remote code execution, necessitating immediate patching.
Vulnerability Details
CVE-ID: CVE-2026-13190
Affected Software: Progress Telerik UI for ASP.NET AJAX
Affected Versions: 2011.2.712 up to (excluding) 2026.2.708
Vulnerability: This vulnerability involves the deserialization of untrusted data (CWE-502) within the persistence framework. An unauthenticated attacker can send crafted malicious input to the application, which, when deserialized, leads to unsafe type resolution and potential execution of arbitrary code.
Business Impact
Deserialization flaws are high-risk vulnerabilities that frequently result in full remote code execution on the underlying server. With a CVSS score of 8.1, this issue represents a major threat to organizational security, potentially allowing attackers to install backdoors, steal sensitive data, or pivot into the internal network. The impact on business continuity and data confidentiality is severe.
Remediation Plan
Immediate Action: Apply the vendor-supplied security update by upgrading to version 2026.2.708 or later.
Proactive Monitoring: Inspect network traffic and server logs for serialized objects or anomalous payload structures directed at the persistence framework endpoints.
Compensating Controls: Implement strict input validation or use a WAF to filter requests containing serialized data structures that do not originate from trusted sources.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. Inherent exploitability for deserialization flaws is typically high, as they often bypass standard authentication mechanisms.
Analyst Recommendation
Deserialization vulnerabilities are a frequent target for attackers due to the potential for complete system takeover. Organizations must treat this CVE with the highest urgency and ensure the provided patch is deployed across all affected instances without delay.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In Progress® Telerik® UI for AJAX prior to v2026
In Progress® Telerik® UI for AJAX prior to v2026
---METADATA---
VENDOR: Progress
PRODUCT: Telerik UI for ASP.NET AJAX
AFFECTED_VERSIONS: 2011.2.712 up to (excluding) 2026.2.708
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Progress Telerik UI for ASP.NET AJAX contains a vulnerability where unauthenticated attackers can use externally controlled input to select arbitrary code or classes for execution.
Executive Summary:
A high-severity vulnerability in Progress Telerik UI for ASP.NET AJAX allows unauthenticated attackers to influence code execution paths, risking unauthorized application behavior.
Vulnerability Details
CVE-ID: CVE-2026-13187
Affected Software: Progress Telerik UI for ASP.NET AJAX
Affected Versions: 2011.2.712 up to (excluding) 2026.2.708
Vulnerability: This flaw involves the use of externally controlled input to select classes or code (CWE-470), which can be exploited by an unauthenticated attacker via the network. By tampering with provider types, an attacker may force the application to execute unintended logic.
Business Impact
The ability to manipulate code selection can lead to arbitrary code execution or significant logic bypass within the application. With a CVSS score of 8.1, this vulnerability poses a severe threat to the integrity and availability of the affected system. Successful exploitation could allow an attacker to gain control over application functions, potentially leading to unauthorized data modification or total service disruption.
Remediation Plan
Immediate Action: Upgrade the Telerik UI for ASP.NET AJAX framework to version 2026.2.708 or higher.
Proactive Monitoring: Review application logs for unexpected provider type values or suspicious requests directed at the DialogHandler, which may indicate tampering attempts.
Compensating Controls: Utilize a Web Application Firewall (WAF) to inspect incoming requests for anomalous input patterns that deviate from expected application behavior.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The complexity of crafting a successful payload against the provider type selection mechanism provides a limited degree of inherent protection.
Analyst Recommendation
Given the potential for unauthorized code execution, immediate remediation is required. Security teams should verify their current version of Telerik UI and apply the provided vendor patch as soon as possible to secure the application environment.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In Progress® Telerik® UI for AJAX prior to v2026
In Progress® Telerik® UI for AJAX prior to v2026
---METADATA---
VENDOR: Progress
PRODUCT: Telerik UI for ASP.NET AJAX
AFFECTED_VERSIONS: 2013.1.220 up to (excluding) 2026.2.708
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A path traversal vulnerability in Progress Telerik UI for ASP.NET AJAX allows unauthenticated attackers to access restricted directories via improper pathname validation.
Executive Summary:
A path traversal vulnerability in Progress Telerik UI for ASP.NET AJAX, assigned a CVSS score of 8.1, poses a significant risk of unauthorized file access and potential system compromise.
Vulnerability Details
CVE-ID: CVE-2026-13186
Affected Software: Progress Telerik UI for ASP.NET AJAX
Affected Versions: 2013.1.220 up to (excluding) 2026.2.708
Vulnerability: This vulnerability is a path traversal flaw (CWE-22) that allows an unauthenticated attacker to manipulate input to access files outside the intended directory. The attack vector is network based and does not require user interaction, though it relies on specific conditions for successful exploitation.
Business Impact
The ability to perform path traversal can lead to the exposure of sensitive configuration files, source code, or internal system data. Given the CVSS score of 8.1, this is a high severity issue that could facilitate further attacks or lead to a complete compromise of the affected web application. Organizations relying on this framework should treat this as a priority to prevent data exfiltration or unauthorized system access.
Remediation Plan
Immediate Action: Update Progress Telerik UI for ASP.NET AJAX to version 2026.2.708 or later as specified in the vendor documentation.
Proactive Monitoring: Monitor web server access logs for unusual patterns, such as multiple occurrences of directory traversal sequences (e.g., ../) in request parameters.
Compensating Controls: Deploy or update rules on your Web Application Firewall (WAF) to detect and block requests containing path traversal characters or suspicious directory navigation attempts.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While the score is high, successful exploitation typically requires specific environmental conditions to be met.
Analyst Recommendation
This vulnerability represents a significant security gap that could be leveraged to bypass intended file access restrictions. We strongly recommend that all administrators prioritize the update to the patched version, 2026.2.708, to eliminate this risk.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In Progress® Telerik® UI for AJAX prior to v2026
In Progress® Telerik® UI for AJAX prior to v2026
---METADATA---
VENDOR: Progress
PRODUCT: Telerik UI for ASP.NET AJAX
AFFECTED_VERSIONS: 2013.1.220 up to (excluding) 2026.2.708
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A deserialization vulnerability in Progress Telerik UI for ASP.NET AJAX allows remote attackers to execute arbitrary code by supplying malicious serialized data.
Executive Summary:
Progress Telerik UI for ASP.NET AJAX contains a deserialization vulnerability that could allow unauthenticated attackers to achieve remote code execution.
Vulnerability Details
CVE-ID: CVE-2026-13185
Affected Software: Progress Telerik UI for ASP.NET AJAX
Affected Versions: 2013.1.220 up to (excluding) 2026.2.708
Vulnerability: This is a deserialization of untrusted data vulnerability (CWE-502) that allows unauthenticated attackers to trigger malicious operations by providing crafted data to the application.
Business Impact
Deserialization flaws are severe, as they often lead to remote code execution. With a CVSS score of 8.1, this vulnerability presents a high risk of total system compromise, including the potential for data exfiltration and the installation of persistent malicious backdoors.
Remediation Plan
Immediate Action: Update Telerik UI for ASP.NET AJAX to version 2026.2.708 or later to resolve the insecure deserialization flaw.
Proactive Monitoring: Review application logs for evidence of malformed serialized objects or abnormal cookie usage that could indicate attempted deserialization attacks.
Compensating Controls: Implement strict input validation and ensure that sensitive data handled by the UI framework is properly encrypted and signed to prevent tampering.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of July 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The technical nature of this flaw makes it highly susceptible to exploitation if the application surface is exposed.
Analyst Recommendation
This vulnerability represents a significant security risk to any web application utilizing the affected Telerik components. Security teams must prioritize patching to version 2026.2.708 immediately to prevent attackers from leveraging this deserialization weakness to gain unauthorized code execution.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In Progress® Telerik® UI for AJAX prior to v2026
In Progress® Telerik® UI for AJAX prior to v2026
---METADATA---
VENDOR: Progress
PRODUCT: Telerik UI for ASP.NET AJAX
AFFECTED_VERSIONS: 2010.1.309 up to (excluding) 2026.2.708
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A vulnerability in Progress Telerik UI for ASP.NET AJAX allows attackers to use externally controlled input to select classes or code, potentially leading to unauthorized execution.
Executive Summary:
Progress Telerik UI for ASP.NET AJAX is affected by a high-severity vulnerability that could allow attackers to manipulate code execution flows via malicious input.
Vulnerability Details
CVE-ID: CVE-2026-13181
Affected Software: Progress Telerik UI for ASP.NET AJAX
Affected Versions: 2010.1.309 up to (excluding) 2026.2.708
Vulnerability: This flaw (CWE-470) involves the use of externally controlled input to select classes or code, which can be exploited by unauthenticated remote attackers to influence application behavior.
Business Impact
The ability to manipulate application code selection poses a significant risk to data confidentiality and integrity. With a CVSS score of 8.1, this vulnerability could facilitate unauthorized access or remote code execution, leading to potential system-wide impact if left unpatched.
Remediation Plan
Immediate Action: Update Telerik UI for ASP.NET AJAX to version 2026.2.708 or later as directed by the vendor.
Proactive Monitoring: Monitor application logs for unexpected class instantiation errors or anomalous requests targeting the Telerik framework components.
Compensating Controls: Utilize a WAF to filter and validate input parameters, specifically looking for attempts to inject unexpected type names or class references.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of July 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability requires careful input handling to mitigate, and upgrading the library is the only definitive fix.
Analyst Recommendation
Given the critical nature of Telerik UI components in many enterprise applications, it is imperative to verify current versions immediately. Organizations should apply the provided patch to version 2026.2.708 to protect against potential exploitation of this code selection flaw.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module)
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module)
---METADATA---
VENDOR: Progress
PRODUCT: MOVEit Transfer
AFFECTED_VERSIONS: 2026.0.0 up to (excluding) 2026.0.1, 2025.1.0 up to (excluding) 2025.1.4, 2025.0.0 up to (excluding) 2025.0.8
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A cross-site scripting (XSS) vulnerability in the Ad Hoc module of Progress MOVEit Transfer allows for improper neutralization of user input during web page generation.
Executive Summary:
A high-severity cross-site scripting vulnerability in Progress MOVEit Transfer exposes authenticated users to potential session hijacking and unauthorized data access.
Vulnerability Details
CVE-ID: CVE-2026-11903
Affected Software: Progress MOVEit Transfer
Affected Versions: 2026.0.0 up to (excluding) 2026.0.1, 2025.1.0 up to (excluding) 2025.1.4, 2025.0.0 up to (excluding) 2025.0.8
Vulnerability: This is a Cross-Site Scripting (XSS) vulnerability located in the Ad Hoc module. An authenticated attacker can inject malicious scripts into web pages, which will execute in the context of the victim's session.
Business Impact
Successful exploitation allows an attacker to execute arbitrary scripts in the browser of an authenticated user. This can lead to the theft of session tokens, unauthorized access to sensitive file transfers, or the manipulation of application data. Given the CVSS score of 8.0, this represents a significant risk to the integrity and confidentiality of data processed within the MOVEit environment.
Remediation Plan
Immediate Action: Upgrade to the latest patched version of MOVEit Transfer as specified in the Progress security bulletin.
Proactive Monitoring: Review web server and application access logs for unusual patterns or suspicious script-related strings within Ad Hoc module request parameters.
Compensating Controls: Deploy a Web Application Firewall (WAF) with strict XSS filtering rules to inspect and sanitize incoming traffic to the Ad Hoc module.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 9, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Organizations should treat this vulnerability with high priority, given the critical nature of file transfer software. Administrators must verify their current version against the affected list and apply the relevant security updates immediately to prevent potential account compromise.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Progress
PRODUCT: Flowmon ADS
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
Progress Flowmon ADS versions prior to 12 are affected by a high-severity vulnerability requiring immediate attention to prevent unauthorized system exploitation.
Executive Summary:
Progress Flowmon ADS versions prior to 12 contain a high-severity security flaw that poses a significant risk to the integrity and availability of the Anomaly Detection System.
Vulnerability Details
CVE-ID: CVE-2026-9272
Affected Software: Progress Flowmon ADS
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This security flaw affects the Anomaly Detection System (ADS) component of the Flowmon suite; administrators should assume the risk of unauthorized access or control if the system remains unpatched.
Business Impact
With a CVSS score of 8.7, this vulnerability threatens the core security monitoring capabilities of the organization. Compromise of the ADS could enable attackers to blind security teams to malicious activity, facilitating long-term persistence within the network.
Remediation Plan
Immediate Action: Apply the vendor-supplied update to upgrade Flowmon ADS to version 12 or the latest recommended release.
Proactive Monitoring: Review audit logs for anomalous account activity or unauthorized configuration changes within the Flowmon ADS console.
Compensating Controls: Utilize network segmentation to isolate the Flowmon ADS management interface from untrusted network segments.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 3, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
The vulnerability in Flowmon ADS represents a critical risk to organizational visibility and incident response capabilities. Remediation via upgrading to version 12 must be executed immediately to ensure the integrity of the anomaly detection environment.