CVE-2026-59687

Progress Software · LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF

An OS command injection vulnerability in the Geo Location management interface of several Progress Software products allows authenticated, high-privileged attackers to execute arbitrary OS commands.

Executive summary

An OS command injection vulnerability in the Geo Location management interface of Progress Software appliances allows high-privileged, authenticated attackers to execute arbitrary commands.

Vulnerability

This flaw is an OS command injection (CWE-78) targeting the Geo Location management functionality. It requires an authenticated attacker with high-level access to trigger the injection through the management interface.

Business impact

Successful exploitation grants an attacker full control over the appliance, which can lead to the compromise of the entire network infrastructure managed by these devices. The CVSS score of 8.4 reflects the high risk of total system compromise and the potential for severe data loss or service downtime.

Remediation

Immediate Action: Update the affected software to version 7.2.63.3 or 7.2.54.19 as specified by the manufacturer.

Proactive Monitoring: Review logs specifically for interactions with the Geo Location management settings to identify any unauthorized or anomalous activity.

Compensating Controls: Disable the Geo Location feature if not strictly required, or isolate the management interface using strict network access control lists.

Exploitation status

Public Exploit Available: No (no weaponized exploit confirmed).

Analyst recommendation

Administrators must treat this as a high-priority update. Promptly apply the provided patches to all affected LoadMaster and related appliances to prevent potential command execution and maintain system security.