Live · collected 51m ago · 29 sources

Live feed

Every story from a named source, linked to it. Ranked by source tier, exploitation status and how many independent outlets carried it.

Exploited only
6 of 1,083 storiesProgressClear all

Latest

Page 1 of 1
Progress·Canadian Centre for Cyber Security·

Progress security advisory (AV26-915)

Serial Number: AV26-915 Date: September 11, 2026 As of September 11, 2026, Progress Software is affected by a vulnerability in the following product: Chef Automate Prior to 4.13.520 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Critical Security Bulletin - August 2026 - Chef Automate Security Vulnerability Progress Trust Center

Oracle · Progress·The Hacker News·

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities

Progress·Canadian Centre for Cyber Security·

Progress Software security advisory (AV26-875)

Serial number: AV26-875 Date: September 2, 2026 As of September 2, 2026, Progress Software is affected by vulnerabilities in the following product: Telerik UI for ASP.NET AJAX Prior to 2026.3.812 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Telerik Web Forms RadImageEditor Path Traversal Vulnerability (CVE-2026-18672) Telerik Web Forms DialogHandler UploadPaths Tampering Vulnerability (CVE-2026-19219)