Attackers can exploit five software vulnerabilities in Progress LoadMaster, ECS Connection Manager, Connection Manager, and Multi-Tenant, and in the worst case, execute their own commands.
The vulnerabilities are listed in the security section of the Progress website . They are all classified with a threat level of “ high ” (CVE-2026-59686, CVE-2026-59687, CVE-2026-59688, CVE-2026-59689, CVE-2026-59690). So far, there are no indications that attackers are already exploiting the vulnerabilities. To protect systems from possible attacks, administrators must install the following repaired versions:
If this is not done, attackers can, among other things, execute their own commands via the management interface and thus completely compromise instances. However, attackers must already be authenticated and have high user privileges for this. In another case, an attacker with low user privileges can gain root privileges through an unspecified method.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
