Critical Progress LoadMaster Flaws Let Attackers Execute Commands, Gain Root Access
Key Takeaways Progress has patched five critical vulnerabilities (CVE-2026-59686 to CVE-2026-59690) in its Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale products....
Key Takeaways
- Progress has patched five critical vulnerabilities (CVE-2026-59686 to CVE-2026-59690) in its Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale products.
- These flaws, including command injection and broken access controls, could allow authenticated attackers to gain root access and complete control over affected appliances.
- Multiple older versions of LoadMaster (GA, LTSF, Multi-Tenant), ECS Connection Manager, and Connection Manager for ObjectScale are impacted.
- Patches are available, and Progress urges immediate upgrades, though no active exploitation has been reported.
Progress has issued a critical security bulletin addressing five severe vulnerabilities across its Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale appliances. These flaws, identified as CVE-2026-59686 through CVE-2026-59690, could enable authenticated attackers to achieve full system compromise, including root access and arbitrary command execution.
Table Of Content
The vendor released its advisory on July 27, 2026. Progress has stated that it currently has no evidence of these vulnerabilities being actively exploited in the wild and is unaware of any customer impact. No indicators of compromise have been released at this time.
Command Injection Vulnerabilities
Three of the disclosed vulnerabilities involve operating system command injection, allowing malicious commands to be run on the underlying system.
- CVE-2026-59686: This vulnerability permits a highly privileged authenticated attacker to execute arbitrary commands directly through the LoadMaster management interface.
- CVE-2026-59687: Similar to CVE-2026-59686, this flaw presents a command injection risk within the Geo Location management interface.
- CVE-2026-59688: This command injection issue resides in the backup and restore functionality. An attacker with high administrative privileges could leverage this to execute commands on the appliance’s operating system.
Successful exploitation of any of these command injection vulnerabilities could grant an attacker complete control over the affected appliance, allowing for data manipulation, service disruption, or further network infiltration.
Broken Access Control Flaws
The remaining two vulnerabilities are related to broken access controls, enabling unauthorized privilege escalation or operations.
- CVE-2026-59689: This is an incorrect authorization flaw that allows a low-privilege authenticated user to escalate their permissions to root. Achieving root access provides an attacker with unrestricted control over the LoadMaster system, including the ability to alter configurations, access sensitive traffic data, establish persistence, or disrupt load-balancing services entirely.
- CVE-2026-59690: This missing authorization vulnerability affects the REST API. It permits low-privileged authenticated users to perform administrative operations that should be restricted based on their assigned roles. This particular flaw also impacts Progress Kemp Multi-Tenant LoadMaster deployments.
Affected Versions and Patches
The vulnerabilities impact several versions of Progress products:
- Progress Kemp LoadMaster, Progress ECS Connection Manager, and Progress Connection Manager for ObjectScale versions 7.2.63.27 and earlier.
- Kemp LoadMaster LTSF version 7.2.54.187 and earlier.
- For Multi-Tenant LoadMaster, CVE-2026-59690 affects version 7.1.35.157 and earlier.
Progress recommends that all affected organizations update their systems immediately to patched versions. Specific upgrade paths are as follows:
- LoadMaster GA users should upgrade to version 7.2.63.37.
- LTSF users should install version 7.2.54.197.
- ECS Connection Manager and Connection Manager for ObjectScale users should upgrade to version 7.2.63.37.
- Multi-Tenant LoadMaster customers should transition to version 7.1.35.167.
Administrators can verify their installed LoadMaster version via the web interface (version string in the upper-right corner) or during appliance console startup. Organizations running unsupported releases are advised to upgrade to a supported, fixed version, as older versions may no longer receive essential security patches.
What You Should Do
- Immediately apply the recommended patches to all affected Progress Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale instances.
- Review and audit all administrative accounts, eliminating any unnecessary privileged access.
- Enforce strong password policies and enable multi-factor authentication (MFA) on all management interfaces and APIs where available.
- Actively monitor management interface and REST API logs for any unusual commands, unauthorized configuration changes, or suspicious activity.
- If using unsupported versions, plan for an upgrade to a currently supported, patched release to ensure ongoing security updates.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.