CVE-2026-3517
CVSS 8.4 HIGH: oS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated… EPSS 4% (91º percentile).
Vulnerabilità · 160 giorni fa
Progress’s ADC appliances are not exposed to drive-by compromise here. The risk starts when an attacker already has high-privilege admin access, because the flaws let that user turn management functions and WAF rule handling into command execution. That makes stolen or misused admin credentials the real threat, not unauthenticated internet scanning.
Progress patched four issues across MOVEit WAF and LoadMaster: CVE-2026-3517, CVE-2026-3519, CVE-2026-3518, and CVE-2026-4048. The affected products include Progress MOVEit WAF, LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale, with fixes in MOVEit WAF 7.2.63.0, LoadMaster GA 7.2.63.1, LoadMaster LTSF 7.2.54.17, ECS Connection Manager 7.2.63.1, and Connection Manager for ObjectScale 7.2.63.1.
The separate CVE-2026-21876 issue is a WAF detection bypass in multipart header handling. It can let a specially crafted request slip past detection, so the remaining risk is not just command execution on the appliance but also traffic that the WAF fails to flag.
CVSS 8.4 HIGH: oS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated… EPSS 4% (91º percentile).
CVSS 8.4 HIGH: oS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated… EPSS 4% (91º percentile).
CVSS 8.4 HIGH: oS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated… EPSS 4% (91º percentile).
CVSS 8.4 HIGH: oS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated… EPSS 4% (91º percentile).
2 fonti che coprono questa storia
Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876) - Help Net Security
Progress Software fixed high-severity vulnerabilities in MOVEit WAF and LoadMaster, including CVE-2026-21876, a firewall bypass flaw.
Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster
The security defects could be exploited for remote code execution, OS command injection, and WAF detection bypass.
Part of the PlainSec briefing for 2026-04-22