Skip to content
Critical Vulnerabilities in Progress LoadMaster Allow Command Execution

Critical Vulnerabilities in Progress LoadMaster Allow Command Execution

First seen 28 Jul 2026, 21:24 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 29, 2026 at 17:47 UTC
  • Five critical vulnerabilities in Progress LoadMaster could lead to complete appliance compromise.
  • Affected CVEs include CVE-2026-59686 through CVE-2026-59690, all published on July 27, 2026.
  • No active exploitation has been reported, but immediate patching is recommended to prevent potential attacks.

Five high-severity vulnerabilities have been identified in Progress LoadMaster and related systems, tracked as CVE-2026-59686 to CVE-2026-59690. These flaws could allow authenticated users to execute arbitrary commands and gain root access, potentially compromising entire appliances. The vulnerabilities affect older versions of Kemp LoadMaster, ECS Connection Manager, and ObjectScale appliances. Progress released a critical security bulletin on July 27, 2026, detailing these issues and recommending immediate updates. Currently, there are no reports of active exploitation, but the vulnerabilities pose a significant risk if left unpatched. Administrators are urged to apply the latest patches to mitigate potential attacks. The vulnerabilities were publicly disclosed on the same day as the advisory.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 54d ago How this analysis works

Timeline

2026-07-27
Critical security bulletin released
Progress issued a bulletin detailing five serious vulnerabilities affecting LoadMaster and related systems, urging immediate updates.
Cybersecuritynews
2026-07-27
CVE-2026-59686 published
CVE-2026-59686, one of five vulnerabilities, was disclosed as part of the security bulletin.
Heise.De
2026-07-27
CVE-2026-59687 published
CVE-2026-59687 was disclosed, highlighting the risk of command execution by authenticated users.
Heise.De
2026-07-27
CVE-2026-59688 published
CVE-2026-59688 was disclosed, part of a series of vulnerabilities affecting multiple systems.
Heise.De
2026-07-27
CVE-2026-59689 published
CVE-2026-59689 was disclosed, indicating potential for complete appliance compromise.
Heise.De
2026-07-27
CVE-2026-59690 published
CVE-2026-59690 was disclosed, emphasizing the critical nature of the vulnerabilities.
Heise.De

More articles in this cluster (14)

Following this threat?

Track Progress and CVE-2026-59686 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed