Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
8.0
CVE-2026-59689PATCHED
progress · loadmaster

Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root

Description

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.

Affected Products

VendorProductVersions
progressloadmaster7.2.36, 7.2.36, 7.2.60.0, 7.2.60.0, 7.2.60.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
progressloadmastercert_advisory90%
progressmoveitcert_advisory90%

References

  • https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-July-2026-CVE-2026-59686-CVE-2026-59687-CVE-2026-59688-CVE-2026-59689-CVE-2026-59690(vendor-advisory)

Related News (5 articles)

Tier B
CERT-FR11d ago
Multiples vulnérabilités dans Progress MOVEit WAF (13 août 2026)
→ No new info (linked only)
Tier B
CCCS Canada26d ago
Progress Software security advisory (AV26-755)
→ No new info (linked only)
Tier D
Heise Security26d ago
Verschiedene Attacken auf Progress LoadMaster möglich
→ No new info (linked only)
Tier B
BSI Advisories26d ago
[NEU] [hoch] Progress Software LoadMaster und MOVEit WAF: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB27d ago
CVE-2026-59689 | Progress Software ECS Connection Manager improper authorization
→ No new info (linked only)
CVSS 3.18.0 HIGH
VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
7.2.63.37.2.54.19
CWECWE-863
PublishedJul 27, 2026
Trending Score15
Source articles5
Independent5
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-16139
Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution
Trending: 22
HIGHCVE-2026-16138
Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO service
Trending: 22
HIGHCVE-2026-16137
Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller
Trending: 22
CRITICALCVE-2026-8037EXPKEV
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Trending: 21
HIGHCVE-2026-59690
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API
Trending: 15

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 27, 2026
Discovered by ZDM
Jul 27, 2026
Patch Available
Jul 28, 2026