High severity8.4NVD Advisory· Published Jul 27, 2026· Updated Aug 11, 2026
CVE-2026-59688
CVE-2026-59688
Description
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.
Affected products
8- cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*Range: <7.2.63.3
- cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*Range: <7.2.63.3
- cpe:2.3:a:progress:moveit_web_application_firewall:*:*:*:*:*:*:*:*Range: <7.2.63.3
Patches
Vulnerability mechanics
References
1News mentions
3- ZDI-26-482: Progress Software Kemp LoadMaster enablexroot Use of Hard-Coded Cryptographic Key Privilege Escalation VulnerabilityZero Day Initiative · Jul 29, 2026
- ZDI-26-481: Progress Software Kemp LoadMaster access Missing Authorization Privilege Escalation VulnerabilityZero Day Initiative · Jul 29, 2026
- Five Progress LoadMaster Flaws Let Attackers Execute Commands and Gain Root AccessCyber Security News · Jul 28, 2026