Progress / LoadMaster
26 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59690 | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation vi… | HIGH | 8.0 | Jul 27, 2026 |
| CVE-2026-59689 | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root | HIGH | 8.0 | Jul 27, 2026 |
| CVE-2026-59688 | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality | HIGH | 8.4 | Jul 27, 2026 |
| CVE-2026-59687 | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface | HIGH | 8.4 | Jul 27, 2026 |
| CVE-2026-59686 | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface | HIGH | 8.4 | Jul 27, 2026 |
| CVE-2026-8037 KEV | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF | CRITICAL | 9.8 | Jun 4, 2026 |
| CVE-2026-4048 | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF | HIGH | 8.4 | Apr 20, 2026 |
| CVE-2026-3519 | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF | HIGH | 8.4 | Apr 20, 2026 |
| CVE-2026-3518 | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF | HIGH | 8.4 | Apr 20, 2026 |
| CVE-2026-3517 | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF | HIGH | 8.4 | Apr 20, 2026 |
| CVE-2025-13447 | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster | HIGH | 8.4 | Jan 13, 2026 |
| CVE-2025-13444 | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster | HIGH | 8.4 | Jan 13, 2026 |
| CVE-2025-1758 | Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions… | HIGH | 8.8 | Mar 19, 2025 |
| CVE-2024-56135 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. | HIGH | 8.4 | Feb 5, 2025 |
| CVE-2024-56134 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. | HIGH | 8.4 | Feb 5, 2025 |
| CVE-2024-56133 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. | HIGH | 8.4 | Feb 5, 2025 |
| CVE-2024-56132 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. | HIGH | 8.4 | Feb 5, 2025 |
| CVE-2024-56131 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. | HIGH | 8.4 | Feb 5, 2025 |
| CVE-2024-8755 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. | CRITICAL | 9.8 | Oct 11, 2024 |
| CVE-2024-6658 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection. | HIGH | 8.4 | Sep 12, 2024 |
| CVE-2024-7591 | Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection | CRITICAL | 10.0 | Sep 5, 2024 |
| CVE-2024-3544 | LoadMaster Hardcoded SSH Key | HIGH | 7.5 | May 2, 2024 |
| CVE-2024-3543 | LoadMaster Reversible Password Encryption Algorithm | HIGH | 7.5 | May 2, 2024 |
| CVE-2024-2449 | LoadMaster Cross-Site Request Forgery (CSRF) | HIGH | 7.5 | Mar 22, 2024 |
| CVE-2024-2448 | LoadMaster Command Injection Vulnerability | HIGH | 8.8 | Mar 22, 2024 |
Showing 1 to 25 of 26 CVEs