CVE-2026-3518
8.4Progress Software · LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF
An authenticated OS command injection vulnerability in Progress ADC products allows remote code execution via unsanitized input in the killsession command.
Executive summary
Progress Software ADC products are vulnerable to remote code execution due to an OS command injection flaw, posing a severe risk to appliance integrity.
Vulnerability
This vulnerability is an OS Command Injection (CWE-77) flaw occurring within the killsession command. It requires an authenticated attacker with administrative (All) permissions to execute arbitrary commands on the underlying appliance.
Business impact
Successful exploitation of this vulnerability allows an attacker to achieve full remote code execution on the affected LoadMaster appliances. Given the CVSS score of 8.4, this represents a high-severity risk that could lead to complete system compromise, unauthorized data access, and potential lateral movement within the network.
Remediation
Immediate Action: Update all affected Progress Software appliances to version V7.2.63.0 or later to patch the vulnerable command handling.
Proactive Monitoring: Review administrative access logs for suspicious activity involving the killsession command or unusual shell executions.
Compensating Controls: Restrict administrative access to the appliance management interface to trusted internal networks or specific IP addresses to limit the attack surface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the potential for total system compromise, organizations should prioritize updating their Progress Software ADC infrastructure to the recommended firmware version. Although the vulnerability requires administrative access, hardening management interfaces and auditing user permissions remains a critical security best practice to prevent exploitation by compromised or malicious accounts.
More Progress Software CVEs
Sources
Originally found and disclosed by Michael Argany of TrendAI Research, per the CVE Program record.