CVE-2026-59687
Progress Software · LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF
An OS command injection vulnerability in the Geo Location management interface of several Progress Software products allows authenticated, high-privileged attackers to execute arbitrary OS commands.
Executive summary
An OS command injection vulnerability in the Geo Location management interface of Progress Software appliances allows high-privileged, authenticated attackers to execute arbitrary commands.
Vulnerability
This flaw is an OS command injection (CWE-78) targeting the Geo Location management functionality. It requires an authenticated attacker with high-level access to trigger the injection through the management interface.
Business impact
Successful exploitation grants an attacker full control over the appliance, which can lead to the compromise of the entire network infrastructure managed by these devices. The CVSS score of 8.4 reflects the high risk of total system compromise and the potential for severe data loss or service downtime.
Remediation
Immediate Action: Update the affected software to version 7.2.63.3 or 7.2.54.19 as specified by the manufacturer.
Proactive Monitoring: Review logs specifically for interactions with the Geo Location management settings to identify any unauthorized or anomalous activity.
Compensating Controls: Disable the Geo Location feature if not strictly required, or isolate the management interface using strict network access control lists.
Exploitation status
Public Exploit Available: No (no weaponized exploit confirmed).
Analyst recommendation
Administrators must treat this as a high-priority update. Promptly apply the provided patches to all affected LoadMaster and related appliances to prevent potential command execution and maintain system security.