Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Progress Software

Progress Software Vendor Cyber Rating & Cyber Score

progress.com

Progress Software (Nasdaq: PRGS) empowers organizations to achieve transformational success in the face of disruptive change. Our software enables our customers to develop,deploy and manage responsible AI-powered applications and digital experiences with agility and ease. Customers get a trusted provider in Progress, with the products, expertise and vision they need to succeed. Over 4 million developers and technologists at hundreds of thousands of enterprises depend on Progress. Learn more at www.progress.com.


Progress Software A.I CyberSecurity Scoring

Progress Software
Company Information
Website:https://www.progress.com/
Employees number:4,227
Number of followers:79,183
NAICS:5112
Industry Type:Software Development
Homepage:progress.com
Progress Software Risk Score (AI oriented)
Between 0 and 549
logo
Progress SoftwareSoftware Development
Updated:
13/07/2026
468/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Progress Software Global Score (TPRM)
xxxx
logo
Progress SoftwareSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Progress Software
Progress SoftwareCritical
Current Score
468C (CRITICAL)
01000
9 incidents
-27.25 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
476Before Incident
JULY 2026
472Before Incident
Vulnerability
10 Jul 2026Progress Software
Citrix and Progress Software: URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress Software Orders Emergency Shutdown of ShareFile Storage Zone Controllers Amid Security Threat

468After Incident
CRITICAL-4
CITPRO1783931784
Progress Software Orders Emergency Shutdown of ShareFile Storage Zone Controllers Amid Security Threat Progress Software has instructed customers to immediately take offline all Windows servers running ShareFile Storage Zone Controllers, citing a "credible external security threat." The company disabled access to affected accounts as a precautionary measure while collaborating with internal and external security experts to investigate the incident. The disruption came to light on July 10 after a customer shared Progress’s advisory on Reddit’s r/sysadmin. Progress later confirmed the issue on its status page, marking Storage Zone Controllers as "not operational" and the incident as under active investigation. The company has not disclosed the nature of the threat, its origin, or whether any data has been compromised though it stated there is no evidence of unauthorized access to ShareFile accounts or cloud-stored data. The Storage Zone Controller, a self-hosted component that allows organizations to retain files on their own infrastructure while using ShareFile’s cloud for management, is the sole affected system. Unlike standard cloud-only ShareFile accounts, these controllers are typically exposed to the internet, increasing their vulnerability. Progress’s decision to mandate a full shutdown rather than issuing a patch suggests the threat may involve an unpatched zero-day flaw, stolen credentials, or an issue within Progress’s own systems. Customers are advised to keep controllers offline until further notice and verify they are running ShareFile Storage Zones Controller version 5.12.4 or later (5.x line) or any 6.x release, which address previously disclosed vulnerabilities. However, Progress has not confirmed whether these updates mitigate the current threat. Organizations with internet-exposed controllers should treat the situation as a potential incident, preserve logs, and scan for unauthorized .aspx files in web directories and storage paths. This is not the first time the Storage Zone Controller has been targeted. In 2023, while under Citrix’s ownership, attackers exploited CVE-2023-24489, an unauthenticated flaw in the same component. The vulnerability was actively exploited, prompting Citrix to sever unpatched controllers from the ShareFile cloud a step Progress has now replicated. Progress itself faced a major breach last year via the MOVEit file-transfer zero-day, which the Clop ransomware group leveraged to compromise over 2,700 organizations. As of now, Progress has not provided a timeline for resolution or details on the threat’s specifics, leaving customers in limbo regarding when they can safely restore operations.
INCIDENT DETAILS -
TYPE
Security Threat
IMPACT
Systems Affected: ShareFile Storage Zone ControllersDowntime: Not operationalOperational Impact: Mandated shutdown of affected systems
DATA BREACH
File Types Exposed: .aspx files
JUNE 2026
503Before Incident
Vulnerability
08 Jun 2026Progress Software
Progress Software: Sitefinity Vulnerabilities Allow Hackers to Steal Plaintext Credentials

Critical Sitefinity CMS Vulnerabilities Expose Enterprises to Credential Theft and Unauthorized Access

499After Incident
CRITICAL-4
PRO1780921490
Critical Sitefinity CMS Vulnerabilities Expose Enterprises to Credential Theft and Unauthorized Access In May 2026, Progress Software issued a critical security advisory for Sitefinity CMS and Sitefinity Insight, warning of five severe vulnerabilities that could allow threat actors to steal credentials, bypass authentication, and gain unauthorized access to enterprise environments. The flaws, primarily affecting the OData and ServiceStack Web Services components, pose significant risks to organizations relying on the platform for web infrastructure. The most severe vulnerability, CVE-2026-7312 (CVSS 10.0), stems from insufficiently protected credentials in OData Web Services, enabling remote attackers to extract plaintext credentials from Sitefinity versions 14.0 through 15.4. Another critical flaw, CVE-2026-7198 (CVSS 9.8), involves improper access control in OData Web Services, allowing unauthorized users to bypass security restrictions in versions 15.4.8623 through 15.4.8629. Three additional high-severity vulnerabilities were also disclosed: - CVE-2026-7195 (CVSS 8.8): Improper input validation in OData Web Services (versions 14.1–15.4). - CVE-2026-7201 (CVSS 8.8): Authorization bypass via user-controlled keys in OData Web Services (versions 15.2–15.4). - CVE-2026-7313 (CVSS 8.7): Insufficiently protected credentials in legacy ServiceStack Web Services (versions 8.0–13.3). Exploitation of these flaws could enable attackers to deploy malicious payloads, exfiltrate sensitive data, or pivot into internal networks, given Sitefinity’s role as a central hub for enterprise web infrastructure. The vulnerabilities affect all supported Microsoft SQL Server databases and OS environments running impacted versions. Progress Software has released version-specific patches to mitigate the risks. Organizations on supported branches must apply the following updates: - 15.4 → 15.4.8630 - 15.3 → 15.3.8531 - 15.2 → 15.2.8441 - 15.1 → 15.1.8335 - 15.0 → 15.0.8234 - 14.4 → 14.4.8152 - 13.3 → 13.3.7652 Unsupported versions require an upgrade to the latest release (15.4.8631). Sitefinity Cloud customers and on-premise administrators can access patches via the Progress Knowledge Base. Security teams are advised to monitor logs for anomalous OData API requests or unexpected administrative access as potential indicators of exploitation.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Credentials, sensitive dataSystems Affected: Sitefinity CMS and Sitefinity Insight (versions 8.0–15.4)Operational Impact: Unauthorized access, potential pivot into internal networksIdentity Theft Risk: High (plaintext credential exposure)
DATA BREACH
Type Of Data Compromised: Credentials, sensitive dataSensitivity Of Data: High (plaintext credentials, administrative access)Data Exfiltration: Potential (if exploited)
MAY 2026
502Before Incident
Vulnerability
30 Apr 2026Progress Software
Progress Software: MOVEit Authentication Bypass Vulnerability Sparks Security Concerns

Critical MOVEit Automation Vulnerabilities Expose Systems to Authentication Bypass and Privilege Escalation

497After Incident
CRITICAL-5
PRO1777883125
Critical MOVEit Automation Vulnerabilities Expose Systems to Authentication Bypass and Privilege Escalation Progress Software has issued an urgent security alert for its MOVEit Automation software, addressing two severe vulnerabilities that could allow attackers to bypass authentication and escalate privileges to gain administrative control. The flaws, disclosed on April 30, 2026, were identified by researchers at Airbus SecLab and pose significant risks, including data exposure and full network compromise. The vulnerabilities are tracked as: - CVE-2026-4670 – An authentication bypass flaw in the service backend command port interface. - CVE-2026-5174 – A privilege escalation issue caused by improper input validation. Exploitation of these weaknesses could enable attackers to take over systems, making immediate patching critical. Progress Software has released fixes for affected versions: - 2025.1.4 and earlier → Upgrade to 2025.1.5 - 2025.0.8 and earlier → Upgrade to 2025.0.9 - 2024.1.7 and earlier → Upgrade to 2024.1.8 Administrators can verify their current version via the MOVEit Automation Web Admin portal under the Help > About section. The only remediation is a full upgrade using the installer from Progress Software, which requires temporary system downtime. Customers with active maintenance can download patches from the Progress Community portal, while those without current licensing must contact a Progress sales representative to secure their systems. Organizations are advised to monitor system audit logs for unusual activity or unauthorized privilege changes.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Data exposureSystems Affected: MOVEit Automation softwareDowntime: Temporary system downtime required for patchingOperational Impact: Full network compromise possible
APRIL 2026
502Before Incident
MARCH 2026
497Before Incident
FEBRUARY 2026
585Before Incident
Breach
11 Feb 2026Progress Software
British Airways and Progress Software: Site Not Available

Major Data Breach Exposes Millions of Records in Global Supply Chain Attack

489After Incident
CRITICAL-96
PROASS1771035896
Cybersecurity Alert: Major Data Breach Exposes Millions of Records in Global Supply Chain Attack A sophisticated supply chain attack has compromised a widely used software provider, exposing sensitive data for millions of users worldwide. The breach, detected in late June 2024, targeted MoveIt Transfer, a managed file transfer (MFT) solution developed by Progress Software, which is utilized by thousands of organizations across finance, healthcare, and government sectors. Attackers exploited a zero-day vulnerability (CVE-2024-5806) in the software, allowing unauthorized access to databases storing confidential files. The Cl0p ransomware gang has claimed responsibility, asserting they exfiltrated terabytes of data, including personal records, financial documents, and intellectual property. While Progress Software released a patch on June 25, 2024, delayed updates left many systems vulnerable, with breaches reported in North America, Europe, and Asia. The incident has triggered regulatory scrutiny, with authorities in the U.S. (CISA), UK (NCSC), and EU (ENISA) issuing advisories. Affected entities include U.S. federal agencies, British Airways, and the BBC, among others. The attack underscores the growing threat of supply chain exploits, where a single vendor compromise can cascade across multiple industries. Investigations remain ongoing to assess the full scope of the breach and potential secondary infections.
INCIDENT DETAILS -
TYPE
Supply Chain Attack, Data Breach, Ransomware
MOTIVATION
Data exfiltration, Financial gain
IMPACT
Data Compromised: Terabytes of data, including personal records, financial documents, and intellectual propertySystems Affected: MoveIt Transfer (MFT) solutionIdentity Theft Risk: High
DATA BREACH
Personal recordsFinancial documentsIntellectual propertyNumber Of Records Exposed: MillionsSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
JANUARY 2026
584Before Incident
DECEMBER 2025
578Before Incident
NOVEMBER 2025
577Before Incident
OCTOBER 2025
573Before Incident
SEPTEMBER 2025
569Before Incident
JANUARY 2024
478Before Incident
Vulnerability
01 Jan 2024Progress Software
Citrix and WhatsUp Gold: INC Ransomware Uses Rust-Based Windows and Linux/ESXi Encryptors in New Attacks

INC Ransomware Emerges as a Top Global Threat, Targeting Critical Sectors with Rust-Based Encryptors

473After Incident
CRITICAL-5
PROCLO1781871843
INC Ransomware Emerges as a Top Global Threat, Targeting Critical Sectors with Rust-Based Encryptors Since its emergence in mid-2023, INC ransomware has rapidly evolved into one of the most prolific ransomware operations, claiming over 800 victims worldwide. Operating under a Ransomware-as-a-Service (RaaS) model, the group recruits affiliates and equips them with advanced tools to scale attacks across industries. Initially focusing on healthcare and education, INC has expanded its targeting to legal services, manufacturing, construction, and technology sectors under regulatory pressure and more likely to pay ransoms quickly. The group employs a double extortion tactic, encrypting files while threatening to leak stolen data on its leak site, compounding operational and reputational risks for victims. A recent report from Acronis highlights significant technical advancements in INC’s toolkit. Both its Windows and Linux/ESXi encryptors have been rewritten in Rust, enabling cross-platform attacks with greater evasion capabilities. The updated Windows variant targets Veeam backup deployments, while the Linux/ESXi version optimizes encryption speed by distinguishing local disks from network shares. Both payloads use partial encryption to maintain system usability while ensuring ransom notes remain visible. INC affiliates leverage legitimate remote access tools including CobaltStrike, AnyDesk, ScreenConnect, and TeamViewer to blend into normal IT activity. They also deploy process terminators like PsKill to disable endpoint defenses before exfiltrating data via rclone and 7-Zip. Credential theft has been refined to target salted DPAPI-encrypted Veeam backups. The group’s influence extends beyond its core operations. Following the 2024 disruption of its source code seller, related ransomware families like Lynx and Knoba emerged with overlapping code, indicating the spread of INC’s tooling into adjacent threat groups. Security researchers have identified multiple vulnerabilities exploited in INC attacks, including CVE-2023-3519 (Citrix NetScaler RCE), CVE-2023-4966 (Citrix Bleed), CVE-2023-35082 (SimpleHelp RMM), and CVE-2024-4885 (WhatsUp Gold RCE). Indicators of compromise (IoCs) include Rust-based encryptor hashes, abused legitimate tools, and ransom note filenames like INC-README.TXT.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData exfiltration
IMPACT
Data Compromised: Stolen data leaked on leak siteWindowsLinux/ESXiOperational Impact: Partial encryption to maintain system usabilityBrand Reputation Impact: Reputational risks due to data leaks
JUNE 2023
647Before Incident
Breach
16 Jun 2023Progress Software
Progress Software Corporation

MOVEit Customer Data Security Breach (2023)

518After Incident
CRITICAL-129
PRO5992159100325
In 2023, Progress Software Corporation suffered a critical data breach in its MOVEit file transfer platform, exploited by the Russian cybercriminal group CL0P. The attack compromised the personal data of ~85 million individuals, with sensitive information leaked on the dark web. Plaintiffs alleged that Progress failed to implement industry-standard cybersecurity measures, including IP restrictions, file-type limitations, vulnerability audits, and real-time monitoring. The breach stemmed from unpatched vulnerabilities, delayed patching, and inadequate notification protocols. Legal proceedings revealed negligence in designing secure software and vetting third-party vendors, leading to lawsuits under negligence, breach of contract, unjust enrichment, and state consumer protection laws. Courts ruled that Progress and its clients (direct users and vendor contracting entities) had a duty to enforce reasonable safeguards, reinforcing liabilities for poor vendor management and cybersecurity lapses. The incident underscored systemic failures in proactive threat detection, timely remediation, and compliance with data privacy statutes, exposing victims to identity theft, fraud, and reputational harm while subjecting Progress to multidistrict litigation and regulatory scrutiny.
INCIDENT DETAILS -
TYPE
Data BreachCyberattackRansomware (Data Exfiltration)
MOTIVATION
Financial GainData Theft for Dark Web SaleExtortion
IMPACT
Personally Identifiable Information (PII)Sensitive Corporate DataMOVEit file transfer platformLegal proceedings (MDL litigation)Reputation damageRegulatory scrutinyMultidistrict litigation by 85 million affected individualsSignificant damage due to high-profile breach and litigationLoss of customer trustNegligence claimsBreach of contractUnjust enrichmentState consumer protection law violations (e.g., Massachusetts Chapter 93A, CCPA)Potential fines and settlementsHigh (PII exposed on dark web)
DATA BREACH
PII (e.g., names, addresses, SSNs)Corporate dataPotentially medical/financial recordsNumber Of Records Exposed: 85 millionSensitivity Of Data: High (includes highly sensitive personal and corporate information)Data Exfiltration: Yes (posted on dark web)Data Encryption: No (data was unencrypted during exfiltration)Personally Identifiable Information: Yes
MAY 2023
575Before Incident
Breach
28 May 2023Progress Software
Greater Rochester Independent Practice Association, Inc.

Data Breach at Greater Rochester Independent Practice Association, Inc. (GRIPA)

499After Incident
CRITICAL-76
GRI348072825
The Maine Office of the Attorney General reported a data breach involving Greater Rochester Independent Practice Association, Inc. (GRIPA) on October 5, 2023. The breach occurred on May 28, 2023, and was discovered on May 31, 2023, involving unauthorized access through an external system breach (hacking), potentially affecting 1,742 individuals. Social Security Numbers were among the compromised data, and GRIPA offered 12 months of identity theft protection services through IDX.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Social Security NumbersIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Social Security NumbersSensitivity Of Data: HighPersonally Identifiable Information: Social Security Numbers
MAY 2023
647Before Incident
Breach
27 May 2023Progress Software
Ernst & Young LLP

Data Breach at Ernst & Young LLP (EY US)

570After Incident
CRITICAL-77
ERN447072725
On August 9, 2023, the Washington State Office of the Attorney General reported a data breach affecting Ernst & Young LLP (EY US). The breach occurred from May 27, 2023, to May 31, 2023, involving a third-party service vulnerability in Progress Software’s MOVEit Transfer solution. The breach affected 1,129 Washington residents, compromising personal data including names, Social Security numbers, and financial information.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesSocial Security numbersfinancial information
DATA BREACH
namesSocial Security numbersfinancial informationSensitivity Of Data: High
MAY 2023
756Before Incident
Ransomware
01 May 2023Progress Software
Progress Software

MOVEit Data Transfer Software Exploit

644After Incident
CRITICAL-112
PRO416050724
In a significant cybersecurity event, Progress Software, the maker of MOVEit, a widely used software for data transfer, was exploited by Russian cybercriminals. The attack targeted several US federal government agencies and could potentially impact hundreds of companies and organizations in the US. Despite the vast scale of the attack, exploiting MOVEit's vulnerabilities, no significant impacts have been reported on federal civilian agencies. The Department of Energy, among other federal entities, acknowledged breaches, fostering urgent investigations and remediation efforts. Notably, sensitive data from institutions like Johns Hopkins University may have been compromised, highlighting the far-reaching implications. This incident underscores the persistent cybersecurity challenges facing enterprises and government entities, emphasizing the need for robust security protocols and rapid response mechanisms to mitigate potential threats.
INCIDENT DETAILS -
TYPE
Cyber Attack
MOTIVATION
Data Theft
IMPACT
Sensitive Data from Institutions like Johns Hopkins University
DATA BREACH
Type Of Data Compromised: Sensitive DataSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Progress Software ?
?
What was Progress Software's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Progress Software's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Progress Software's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Progress Software's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Progress Software's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Progress Software's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Progress Software's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Progress Software's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Progress Software's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Progress Software's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Progress Software's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Progress Software's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Progress Software ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Progress Software's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Progress Software Cyber Scoring History | Rankiteo