- EPSS 0.18%
- Veröffentlicht 27.07.2026 12:26:27
- Zuletzt bearbeitet 11.08.2026 14:11:42
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative ope...
- EPSS 0.17%
- Veröffentlicht 27.07.2026 12:25:22
- Zuletzt bearbeitet 11.08.2026 14:12:35
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appl...
CVE-2026-59688
- EPSS 0.72%
- Veröffentlicht 27.07.2026 12:24:23
- Zuletzt bearbeitet 11.08.2026 14:12:51
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the...
CVE-2026-59687
- EPSS 0.72%
- Veröffentlicht 27.07.2026 12:23:15
- Zuletzt bearbeitet 11.08.2026 14:13:02
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the...
CVE-2026-59686
- EPSS 0.74%
- Veröffentlicht 27.07.2026 12:22:05
- Zuletzt bearbeitet 11.08.2026 14:13:12
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the...
CVE-2026-8037
- EPSS 99.31%
- Veröffentlicht 04.06.2026 13:13:45
- Zuletzt bearbeitet 10.08.2026 20:19:44
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
CVE-2025-13444
- EPSS 26.5%
- Veröffentlicht 13.01.2026 14:26:50
- Zuletzt bearbeitet 10.08.2026 20:20:00
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input i...