Back

CRITICAL KEV

OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF

Published Jun 4, 2026 ·Due Aug 10, 2026

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Affected products

Remediation

Vendor solution

plain text

Metrics

Weaknesses (1)

References (4)

Change history (3)
  1. CISA ADP
    • SSVC exploitation changed from poc to active
  2. CISA ADP
    • SSVC exploitation changed from active to poc
  3. CISA ADP
    • SSVC exploitation changed from poc to active
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ProgressSoftware
Published Jun 4, 2026
Updated Oct 1, 2026
Reserved May 6, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Analyzed
Modified Aug 10, 2026
Red Hat
Severity n/a
Public date n/a