Junglewise Threat Intelligence

CVE-2026-59688: Progress Software LoadMaster OS command injection in backup restore

CVE-2026-59688 · Severity: high · CVSS 8.4 · Published 2026-07-27

Vendors: Progress Software.

Executive brief

Progress Software has identified a security vulnerability in several of its networking and data transfer appliances, including LoadMaster and MOVEit WAF. These devices are typically used to manage web traffic and secure file transfers. If exploited, a high-privileged attacker could take full control of the device, potentially leading to data theft, service interruptions, or a complete compromise of the appliance.

Technical details

An OS command injection vulnerability (CWE-78) exists in the backup restore functionality of multiple Progress Software appliances. The flaw allows an authenticated attacker with high privileges to bypass intended restrictions and execute arbitrary commands at the operating system level. The attack vector is classified as 'Adjacent,' meaning the attacker must have access to the local network or a shared segment. Successful exploitation can lead to a complete system compromise (High impact to Confidentiality, Integrity, and Availability) with a scope change. Patches have been released in version 7.2.63.3 and 7.2.54.19 for the respective product lines.

Affected products

  • Progress Software LoadMaster 7.2.40.0 to 7.2.63.2, 7.2.40.0 to 7.2.54.18
  • Progress Software ECS Connection Manager 7.2.60.0 to 7.2.63.2
  • Progress Software Object Scale Connection Manager 7.2.60.0 to 7.2.63.2
  • Progress Software MOVEit WAF 7.2.60.0 to 7.2.63.2

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: disclosed

References