Admin Access Turns Progress ADC Into Command Execution Risk
Progress’s ADC appliances are not exposed to drive-by compromise here. The risk starts when an attacker already has high-privilege admin access, because the flaws let that user turn management functions and WAF rule handling into command execution. That makes stolen or misused admin credentials the real threat, not unauthenticated internet scanning.
Progress patched four issues across MOVEit WAF and LoadMaster: CVE-2026-3517, CVE-2026-3519, CVE-2026-3518, and CVE-2026-4048. The affected products include Progress MOVEit WAF, LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale, with fixes in MOVEit WAF 7.2.63.0, LoadMaster GA 7.2.63.1, LoadMaster LTSF 7.2.54.17, ECS Connection Manager 7.2.63.1, and Connection Manager for ObjectScale 7.2.63.1.
The separate CVE-2026-21876 issue is a WAF detection bypass in multipart header handling. It can let a specially crafted request slip past detection, so the remaining risk is not just command execution on the appliance but also traffic that the WAF fails to flag.