Skip to content
Progress SoftwareCVE-2026-59687

Progress Software ECS Connection Manager: command injection

High8.4CVE-2026-59687 · Published Jul 27, 2026 · updated Aug 11, 2026

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.

Progress Software advisory

Affected versions

PackageAffectedFixed in
ECS Connection Manager
Product
>= 7.2.60.0, < 7.2.63.37.2.63.3
LoadMaster
Product
>= 7.0.8, < 7.2.63.37.2.63.3
>= 7.0.8, < 7.2.54.197.2.54.19
MOVEit WAF
Product
>= 7.2.60.0, < 7.2.63.37.2.63.3
Object Scale Connection Manager
Product
>= 7.2.60.0, < 7.2.63.37.2.63.3
Details and references

More Progress Software advisories

All Progress Software
Advisory
Progress Software ECS Connection Manager: command injection
High8.4Jul 27
Progress Software ECS Connection Manager: improper authorization
High8.0Jul 27
Progress Software ECS Connection Manager: missing authorization
High8.0Jul 27
Progress Software ECS Connection Manager: command injection
High8.4Jul 27
Progress Software MOVEit Transfer: cross-site scripting
High7.1Jul 23
Permissive cross-domain security policy with untrusted domains vulnerability in...
High7.5Jul 23

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.