CVE-2026-3518

8.4

Progress Software · LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF

An authenticated OS command injection vulnerability in Progress ADC products allows remote code execution via unsanitized input in the killsession command.

Executive summary

Progress Software ADC products are vulnerable to remote code execution due to an OS command injection flaw, posing a severe risk to appliance integrity.

Vulnerability

This vulnerability is an OS Command Injection (CWE-77) flaw occurring within the killsession command. It requires an authenticated attacker with administrative (All) permissions to execute arbitrary commands on the underlying appliance.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve full remote code execution on the affected LoadMaster appliances. Given the CVSS score of 8.4, this represents a high-severity risk that could lead to complete system compromise, unauthorized data access, and potential lateral movement within the network.

Remediation

Immediate Action: Update all affected Progress Software appliances to version V7.2.63.0 or later to patch the vulnerable command handling.

Proactive Monitoring: Review administrative access logs for suspicious activity involving the killsession command or unusual shell executions.

Compensating Controls: Restrict administrative access to the appliance management interface to trusted internal networks or specific IP addresses to limit the attack surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the potential for total system compromise, organizations should prioritize updating their Progress Software ADC infrastructure to the recommended firmware version. Although the vulnerability requires administrative access, hardening management interfaces and auditing user permissions remains a critical security best practice to prevent exploitation by compromised or malicious accounts.

More Progress Software CVEs

Sources

Originally found and disclosed by Michael Argany of TrendAI Research, per the CVE Program record.