CVE-2026-59686

Progress Software · LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF

An OS command injection vulnerability exists in multiple Progress Software appliances, allowing authenticated, high-privileged attackers to execute arbitrary commands via the management interface.

Executive summary

An OS command injection vulnerability in Progress Software appliances allows high-privileged, authenticated attackers to execute arbitrary commands, resulting in full system compromise.

Vulnerability

This is an OS command injection vulnerability (CWE-78) triggered through the management interface. It requires an attacker to have high privileges to successfully inject and execute operating system commands.

Business impact

The ability to execute arbitrary OS commands on network appliances leads to complete system takeover. With a CVSS score of 8.4, this vulnerability enables attackers to intercept traffic, modify configurations, or pivot into the internal environment, causing significant operational disruption and data exposure.

Remediation

Immediate Action: Apply the vendor-provided security updates to reach version 7.2.63.3 or 7.2.54.19 immediately.

Proactive Monitoring: Audit management interface access logs for unusual command execution patterns or unauthorized configuration changes.

Compensating Controls: Restrict access to the management interface to authorized, segmented networks and utilize a WAF to inspect traffic for injection signatures.

Exploitation status

Public Exploit Available: No (no weaponized exploit confirmed).

Analyst recommendation

The severity of this flaw necessitates immediate patching of all affected Progress Software appliances. Ensure that administrative access to management interfaces is strictly controlled and monitored to prevent exploitation by malicious actors.