Executive brief
Progress Software has identified a critical vulnerability in several of its networking and data management appliances, including LoadMaster and MOVEit WAF. These devices are used to manage network traffic and secure web applications. An attacker with high-level administrative access could exploit this flaw to take full control of the device, potentially leading to data theft or a complete shutdown of network services.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Geo Location management interface of Progress Software LoadMaster and related connection management appliances. The flaw allows an authenticated attacker with high privileges to bypass input validation and execute arbitrary operating system commands on the underlying appliance. The attack vector is classified as 'Adjacent' (AV:A), implying the attacker must be on the same local network or layer 2 segment. Successful exploitation can lead to a complete system compromise with a 'Changed' scope (S:C) impact. Progress Software has released patches to address this issue in versions 7.2.63.3 and 7.2.54.19.
Affected products
- Progress Software LoadMaster 7.0.8 to 7.2.63.2, 7.0.8 to 7.2.54.18
- Progress Software ECS Connection Manager 7.2.60.0 to 7.2.63.2
- Progress Software Object Scale Connection Manager 7.2.60.0 to 7.2.63.2
- Progress Software MOVEit WAF 7.2.60.0 to 7.2.63.2
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory