Critical Vulnerabilities in Progress LoadMaster Allow Command Execution

Critical Vulnerabilities in Progress LoadMaster Allow Command Execution

First seen 28 Jul 2026, 21:24 UTC CybersecuritynewsHeise.Decommunity.progress.com 88% similarity 72.0

Article Content

Browse articles
ThreatCluster

Five high-severity vulnerabilities have been identified in Progress LoadMaster and related systems, tracked as CVE-2026-59686 to CVE-2026-59690. These flaws could allow authenticated users to execute arbitrary commands and gain root access, potentially compromising entire appliances. The vulnerabilities affect older versions of Kemp LoadMaster, ECS Connection Manager, and ObjectScale appliances. Progress released a critical security bulletin on July 27, 2026, detailing these issues and recommending immediate updates. Currently, there are no reports of active exploitation, but the vulnerabilities pose a significant risk if left unpatched. Administrators are urged to apply the latest patches to mitigate potential attacks. The vulnerabilities were publicly disclosed on the same day as the advisory.

Key Points: • Five critical vulnerabilities in Progress LoadMaster could lead to complete appliance compromise. • Affected CVEs include CVE-2026-59686 through CVE-2026-59690, all published on July 27, 2026. • No active exploitation has been reported, but immediate patching is recommended to prevent potential attacks.

ThreatCluster AI How this analysis works

Timeline

2026-07-27
Critical security bulletin released
Progress issued a bulletin detailing five serious vulnerabilities affecting LoadMaster and related systems, urging immediate updates.
Cybersecuritynews
2026-07-27
CVE-2026-59686 published
CVE-2026-59686, one of five vulnerabilities, was disclosed as part of the security bulletin.
Heise.De
2026-07-27
CVE-2026-59687 published
CVE-2026-59687 was disclosed, highlighting the risk of command execution by authenticated users.
Heise.De
2026-07-27
CVE-2026-59688 published
CVE-2026-59688 was disclosed, part of a series of vulnerabilities affecting multiple systems.
Heise.De
2026-07-27
CVE-2026-59689 published
CVE-2026-59689 was disclosed, indicating potential for complete appliance compromise.
Heise.De
2026-07-27
CVE-2026-59690 published
CVE-2026-59690 was disclosed, emphasizing the critical nature of the vulnerabilities.
Heise.De

Community

Browse all →