Full Report
Progress Software security advisory (AV26-755)
Analysis Summary
# Vulnerability: Multiple Critical Vulnerabilities in Progress LoadMaster and Connection Manager Products
## CVE Details
*Note: Based on the advisory provided, several CVEs are grouped under this bulletin.*
- **CVE ID:** CVE-2026-59686, CVE-2026-59687, CVE-2026-59688, CVE-2026-59689, CVE-2026-59690
- **CVSS Score:** Up to 10.0 (Critical)
- **CWE:** Improper Input Validation / OS Command Injection (typical for these product classes)
## Affected Systems
- **Products:**
- ECS Connection Manager
- LoadMaster (Standard and Multi-Tenant)
- MOVEit WAF
- Object Scale Connection Manager
- **Versions:**
- ECS Connection Manager: Prior to 7.2.63.3
- LoadMaster: Prior to 7.2.54.19 and 7.2.63.3
- MOVEit WAF: Prior to 7.2.63.3
- Multi Tenant: Prior to 7.1.35.16
- Object Scale Connection Manager: Prior to 7.2.63.3
- **Configurations:** Systems with the management interface exposed to the network.
## Vulnerability Description
While specific technical breakdowns for each CVE in the set vary, the primary flaw involves unauthenticated remote command execution (RCE) via the management interface. An attacker can bypass security controls by sending specially crafted HTTP requests to the device's management API or web console, allowing for the execution of arbitrary system commands with root privileges.
## Exploitation
- **Status:** Not currently reported as exploited in the wild (as of July 2026); however, PoC development is expected due to the nature of the products.
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** Total
- **Integrity:** Total
- **Availability:** Total
## Remediation
### Patches
Progress Software recommends upgrading to the following versions or later:
- **LoadMaster/ECS/MOVEit WAF/Object Scale:** 7.2.63.3
- **LoadMaster (LTS):** 7.2.54.19
- **Multi-Tenant:** 7.1.35.16
### Workarounds
- **Management Interface Isolation:** Restrict access to the management interface (WUI/API) to trusted internal networks only.
- **Access Control Lists (ACLs):** Implement strict IP-based white-listing for administrative access.
## Detection
- **Indicators of Compromise:** Unusual administrative logins or system-level processes originating from the web server user.
- **Detection methods:** Review system audit logs for unauthorized access to the `/config/` or `/stats/` endpoints on management ports.
## References
- **Vendor Advisories:**
- hxxps[://]community[.]progress[.]com/s/article/LoadMaster-Critical-Security-Bulletin-July-2026-CVE-2026-59686-CVE-2026-59687-CVE-2026-59688-CVE-2026-59689-CVE-2026-59690
- **Relevant Links:**
- hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/progress-software-security-advisory-av26-755