Progress SoftwareCVE-2026-59687
Progress Software ECS Connection Manager: command injection
High8.4CVE-2026-59687 · Published Jul 27, 2026 · updated Aug 11, 2026
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ECS Connection Manager Product | >= 7.2.60.0, < 7.2.63.3 | 7.2.63.3 |
| LoadMaster Product | >= 7.0.8, < 7.2.63.3 | 7.2.63.3 |
| >= 7.0.8, < 7.2.54.19 | 7.2.54.19 | |
| MOVEit WAF Product | >= 7.2.60.0, < 7.2.63.3 | 7.2.63.3 |
| Object Scale Connection Manager Product | >= 7.2.60.0, < 7.2.63.3 | 7.2.63.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 27 | Progress Software ECS Connection Manager: command injection | High8.4 | LoadMaster 7.2.63.3+2 more |
| Jul 27 | Progress Software ECS Connection Manager: improper authorization | High8.0 | LoadMaster 7.2.63.3+2 more |
| Jul 27 | Progress Software ECS Connection Manager: missing authorization | High8.0 | LoadMaster 7.2.63.3+2 more |
| Jul 27 | Progress Software ECS Connection Manager: command injection | High8.4 | LoadMaster 7.2.63.3+2 more |
| Jul 23 | Progress Software MOVEit Transfer: cross-site scripting | High7.1 | 2025.1.5+1 more |
| Jul 23 | Permissive cross-domain security policy with untrusted domains vulnerability in... | High7.5 | 2025.1.5+1 more |