CVE-2026-3519

8.4

Progress Software · LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF

An OS command injection vulnerability in Progress ADC products allows authenticated attackers with VS Administration permissions to execute arbitrary commands via the aclcontrol command.

Executive summary

An authenticated remote code execution vulnerability in Progress Software ADC products poses a severe risk to appliance integrity and network security.

Vulnerability

This is an OS command injection vulnerability (CWE-77) triggered by unsanitized input within the aclcontrol command. It requires the attacker to possess VS Administration privileges to successfully execute arbitrary system commands.

Business impact

The vulnerability carries a CVSS score of 8.4, reflecting its high potential for system compromise. Successful exploitation grants an attacker the ability to execute commands with elevated privileges, leading to full system takeover, potential data exfiltration, or complete disruption of critical load balancing and traffic management services.

Remediation

Immediate Action: Update all affected Progress Software appliances to version V7.2.63.0 or later as specified in the vendor security advisory.

Proactive Monitoring: Review administrative access logs for unusual activity associated with the aclcontrol command or suspicious shell execution patterns.

Compensating Controls: Restrict administrative access to the management interface by enforcing strict IP whitelisting and utilizing Multi-Factor Authentication for all accounts with VS Administration permissions.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS severity and the critical nature of these ADC appliances, organizations must prioritize the application of the vendor-provided security patches. Administrators should verify their current firmware versions immediately and transition to the patched release to eliminate the command injection vector.

More Progress Software CVEs

Sources