Progress Software News Articles
Recent news articles refferecing the vendors vulnerabilities.
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
CISA has added a critical Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog after attackers were observed targeting exposed devices. Tracked as CVE-2026-8037, the flaw affects Progress LoadMaster and Progress ADC products.
5 days ago

CISA Flags Progress LoadMaster Command Injection Vulnerability Exploited in the Wild - IT Security News
2026-08-10 15:08 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability in Progress LoadMaster, tracked as CVE-2026-8037, to its...
5 days ago
Critical Progress LoadMaster flaw now actively exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability.
6 days ago
CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability
CISA urges federal agencies to immediately patch CVE-2026-8037, an exploited remote code execution flaw in Progress LoadMaster.
6 days ago
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
CISA adds Progress Kemp LoadMaster CVE-2026-8037 to KEV after active exploitation reports, with 792 attempts logged across 65 IPs in 41 days.
1 week ago
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
Ravie LakshmananJul 01, 2026Vulnerability / Network Security
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
eSentire says attacks began June 29 against a CVSS 9.6 OS command injection flaw that enables unauthenticated code execution.
Critical Progress Kemp LoadMaster Vulnerability Enables Pre-Auth Remote Code Execution
CVE-2026-8037 lets unauthenticated attackers run commands on Progress Kemp LoadMaster edge appliances, risking enterprise networks.

Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
CVE-2026-8037 in Progress Kemp LoadMaster allows pre-auth root command execution via API; patches are available and a public PoC is out.
Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass
MOVEit Automation flaws (CVE-2026-4670, CVE-2026-5174) enable bypass and escalation, risking enterprise data exposure.
Progress warns of critical MOVEit Automation auth bypass flaw
Progress Software warned customers to patch a critical authentication bypass vulnerability in its MOVEit Automation enterprise-grade managed file transfer (MFT) application.
Critical Telerik UI Flaw Puts Millions of Enterprise Applications at Risk
CVE-2025-3600 affects 14 years of Telerik UI releases, enabling DoS attacks and potential RCE.
More Than DoS (Progress Telerik UI for ASP.NET AJAX Unsafe Reflection CVE-2025-3600)
Welcome back. We’re excited to yet again publish memes under the guise of research and inevitably receive hate mail. But today, we’ll be doing something slightly different to normal. “Wow, watchTowr, will you actually be publishing useful information instead of memes?” Today, instead of pulling ap...
Unsafe Deserialization Vulnerability CVE-2024-10095 - Telerik UI for WPF
How to mitigate CVE-2024-10095, an unsafe deserialization vulnerability.
Cisco, Hitachi, Microsoft, and Progress Flaws Actively Exploited—CISA Sounds Alarm
CISA adds five exploited vulnerabilities to its KEV catalog, including flaws in Cisco, Microsoft, and Progress software.
PoC exploit for critical WhatsUp Gold RCE vulnerability released (CVE-2024-8785) - Help Net Security
Researchers have published a proof-of-concept (PoC) exploit for CVE-2024-8785, a critical remote code execution flaw in Progress WhatsUp Gold.
Exploit released for critical WhatsUp Gold RCE flaw, patch now
A proof-of-concept (PoC) exploit for a critical-severity remote code execution flaw in Progress WhatsUp Gold has been published, making it critical to install the latest security updates as soon as possible.
CISA Warns Kemp LoadMaster OS Command Injection Vulnerability Exploited in Attacks
CISA issued an urgent security advisory warning organizations about an active exploitation of a vulnerability in Progress Kemp LoadMaster.
CISA Warns of Progress Kemp LoadMaster Vulnerability Exploitation
CISA is warning organizations that CVE-2024-1212, a Kemp LoadMaster OS command injection vulnerability, is being exploited in attacks.
CISA tags Progress Kemp LoadMaster flaw as exploited in attacks
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added three new flaws in its Known Exploited Vulnerabilities (KEV) catalog, including a critical OS command injection impacting Progress Kemp LoadMaster.
Warning: VMware vCenter and Kemp LoadMaster Flaws Under Active Exploitation
Critical flaws in Progress Kemp LoadMaster and VMware vCenter Server are under active exploitation, warns CISA.
Recent WhatsUp Gold Vulnerabilities Possibly Exploited in Ransomware Attacks
Two recently patched Progress Software WhatsUp Gold vulnerabilities may have been exploited in the wild, possibly in ransomware attacks.
Hackers targeting WhatsUp Gold with public exploit since August
Hackers have been leveraging publicly available exploit code for two critical vulnerabilities in the WhatsUp Gold network availability and performance monitoring solution from Progress Software.
Critical CVE-2024-4885 Flaw In WhatsUp Gold Exposes Systems
Progress Software’s WhatsUp Gold has a severe CVE-2024-4885 flaw allowing remote code execution.