Executive brief
Progress Software has identified a security flaw in several of its networking and data management appliances, including LoadMaster and MOVEit WAF. These devices are typically used to manage web traffic and secure data transfers. An attacker with administrative access to the management interface could exploit this vulnerability to take full control of the device, potentially leading to data theft or a complete shutdown of the services the appliance supports.
Technical details
An OS Command Injection vulnerability (CWE-78) exists in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. The flaw is located within the management interface and can be triggered by an authenticated attacker with high privileges. By sending specially crafted input to the management interface, the attacker can bypass input validation to execute arbitrary operating system commands with the privileges of the application. This can lead to a complete system compromise. The vulnerability is addressed in versions 7.2.63.3 and 7.2.54.19.
Affected products
- Progress Software Corporation LoadMaster < 7.2.63.3, < 7.2.54.19
- Progress Software Corporation ECS Connection Manager 7.2.60.0 - 7.2.63.2
- Progress Software Corporation Object Scale Connection Manager 7.2.60.0 - 7.2.63.2
- Progress Software Corporation MOVEit WAF 7.2.60.0 - 7.2.63.2
Timeline
- 2026-07-27: advisory: Initial publication of the security bulletin by Progress Software.
- 2026-07-27: disclosed