SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-59688

HIGH · CVSS 8.4 EPSS 0.72%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

An OS Command Injection vulnerability in Progress Software's LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows authenticated attackers with elevated privileges to execute arbitrary commands on the affected systems through the backup restore feature. This could lead to a complete compromise of the system, making it critical for organizations using these products to prioritize patching and remediation efforts. Security teams should act swiftly to mitigate the risk associated with this high-severity vulnerability.

CVE
CVE-2026-59688
Severity
HIGH
CVSS
8.4
EPSS
0.72%

Original NVD Description

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.

Related CVEs

Other vulnerabilities affecting the same vendor(s)