SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-59687

HIGH · CVSS 8.4 EPSS 0.72%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

An OS Command Injection vulnerability exists in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF, allowing authenticated attackers with high privileges to execute arbitrary commands through the Geo Location management interface. This could lead to complete system compromise, making it critical for organizations using these products to prioritize patching and mitigation efforts. Security teams and system administrators should address this vulnerability urgently to protect their environments from potential exploitation.

CVE
CVE-2026-59687
Severity
HIGH
CVSS
8.4
EPSS
0.72%

Original NVD Description

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.

Related CVEs

Other vulnerabilities affecting the same vendor(s)