CVE-2026-3517

8.4

Progress Software · LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF

Progress Software ADC products are vulnerable to OS command injection via the addcountry command, allowing authenticated users with Geo Administration permissions to execute arbitrary system commands.

Executive summary

A critical OS command injection vulnerability in Progress Software ADC products allows authenticated attackers to achieve remote code execution on the underlying appliance.

Vulnerability

The vulnerability is an OS command injection flaw (CWE-77) triggered by unsanitized input within the addcountry command, which can be exploited by an authenticated user holding Geo Administration privileges.

Business impact

Successful exploitation allows an attacker to execute arbitrary commands on the appliance with high-level privileges, potentially leading to full system compromise. Given the CVSS score of 8.4, this vulnerability represents a significant risk to the integrity and availability of network traffic management infrastructure. An attacker could leverage this access to intercept data, modify configurations, or disrupt critical business services.

Remediation

Immediate Action: Update all affected Progress Software appliances to version V7.2.63.0 or later as specified in the official vendor security advisory.

Proactive Monitoring: Review administrative access logs for unusual activity involving the addcountry command and monitor system processes for unauthorized command execution.

Compensating Controls: Restrict administrative access to the Geo Administration interface to a strictly defined list of trusted internal IP addresses and implement Web Application Firewall rules to inspect and filter malicious input patterns targeting the management API.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations should prioritize the identification and update of all affected Progress Software ADC appliances. Because this vulnerability grants command-level access to critical infrastructure, applying the vendor-provided updates is the only definitive way to eliminate the risk of remote code execution.

More Progress Software CVEs

Sources

Originally found and disclosed by Michael Argany of TrendAI Research, per the CVE Program record.