CVE-2026-59686
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface
CVSS Score
8.4
EPSS Score
0.0%
EPSS Percentile
0th
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.
| CWE | CWE-78 |
| Vendor | progress software |
| Product | loadmaster |
| Published | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for progress software loadmaster
Be the first to know when new high vulnerabilities affecting progress software loadmaster are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Progress Software / LoadMaster
All Previous Versions < 7.2.63.3 All Previous Versions < 7.2.54.19
Progress Software / ECS Connection Manager
7.2.60.0 < 7.2.63.3
Progress Software / Object Scale Connection Manager
7.2.60.0 < 7.2.63.3
Progress Software / MOVEit WAF
7.2.60.0 < 7.2.63.3