Progress Software disclosed five high-severity vulnerabilities affecting LoadMaster, ECS Connection Manager, Connection Manager for ObjectScale, MOVEit WAF, and, for one issue, Multi-Tenant LoadMaster. The flaws, tracked as CVE-2026-59686 through CVE-2026-59690, include three authenticated OS command injection bugs and two authorization failures. CVE-2026-59689 can let a low-privileged authenticated user escalate to root, while CVE-2026-59690 allows unauthorized administrative actions through the REST API; the command injection issues (CVE-2026-59686, CVE-2026-59687, and CVE-2026-59688) affect the management interface, Geo Location management interface, and backup restore functionality, respectively.
Progress said it has no reports of active exploitation, no known direct customer impact, and no indicators of compromise so far, but warned that successful exploitation could lead to full appliance compromise. The vulnerabilities carry CVSS 3.1 scores of 8.0 to 8.4, affect older product releases, and require authentication, prompting the vendor to urge immediate upgrades to fixed versions. Defenders are advised to tighten privileged account access, enforce strong authentication controls such as MFA where available, and closely monitor management interfaces and REST API activity for suspicious behavior.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
In the July 27, 2026 disclosure, Progress stated it had no reports of active exploitation, no known direct customer impact, and no indicators of compromise related to the five vulnerabilities. The company urged customers to upgrade to fixed versions and strengthen administrative security and monitoring.
On 2026-07-27, Progress disclosed five vulnerabilities affecting LoadMaster, ECS Connection Manager, Connection Manager for ObjectScale, MOVEit WAF, and for one flaw Multi-Tenant LoadMaster. The issues, tracked as CVE-2026-59686 through CVE-2026-59690, include three authenticated OS command injection flaws and two authorization flaws that could enable privileged actions or root compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecommunity.progress.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.