High severity8.4NVD Advisory· Published Jul 27, 2026· Updated Aug 11, 2026
CVE-2026-59686
CVE-2026-59686
Description
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.
Affected products
8- cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*Range: <7.2.63.3
- cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*Range: <7.2.63.3
- cpe:2.3:a:progress:moveit_web_application_firewall:*:*:*:*:*:*:*:*Range: <7.2.63.3
Patches
Vulnerability mechanics
References
1News mentions
4- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThe Hacker News · Aug 3, 2026
- ZDI-26-482: Progress Software Kemp LoadMaster enablexroot Use of Hard-Coded Cryptographic Key Privilege Escalation VulnerabilityZero Day Initiative · Jul 29, 2026
- ZDI-26-481: Progress Software Kemp LoadMaster access Missing Authorization Privilege Escalation VulnerabilityZero Day Initiative · Jul 29, 2026
- Five Progress LoadMaster Flaws Let Attackers Execute Commands and Gain Root AccessCyber Security News · Jul 28, 2026