CVE-2026-59686: Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59686?
CVE-2026-59686 has a severity score of 8.4, classifying it as high risk.
How do I fix CVE-2026-59686?
To mitigate CVE-2026-59686, apply the latest security patches provided by Progress Software for the affected products.
Who is affected by CVE-2026-59686?
CVE-2026-59686 affects users of Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF.
What type of vulnerability is CVE-2026-59686?
CVE-2026-59686 is classified as an OS Command Injection vulnerability.
What are the potential impacts of CVE-2026-59686?
An attacker may exploit CVE-2026-59686 to execute arbitrary operating system commands on the affected appliance.