Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical LegacyHive Exploits Bypass Windows Security, Even With July 2026 Patches
July 28, 2026
Critical libssh2 Vulnerabilities Let Malicious SSH Servers Corrupt Client Memory
July 28, 2026
Critical Arista VeloCloud Orchestrator Zero-Day Actively Exploited
July 28, 2026
Home/CyberSecurity News/Critical Progress LoadMaster Flaws Let Attackers Execute Commands, Gain Root Access
CyberSecurity News

Critical Progress LoadMaster Flaws Let Attackers Execute Commands, Gain Root Access

Key Takeaways Progress has patched five critical vulnerabilities (CVE-2026-59686 to CVE-2026-59690) in its Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale products....

David kimber
David kimber
July 28, 2026 3 Min Read
2 0

Key Takeaways

  • Progress has patched five critical vulnerabilities (CVE-2026-59686 to CVE-2026-59690) in its Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale products.
  • These flaws, including command injection and broken access controls, could allow authenticated attackers to gain root access and complete control over affected appliances.
  • Multiple older versions of LoadMaster (GA, LTSF, Multi-Tenant), ECS Connection Manager, and Connection Manager for ObjectScale are impacted.
  • Patches are available, and Progress urges immediate upgrades, though no active exploitation has been reported.

Progress has issued a critical security bulletin addressing five severe vulnerabilities across its Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale appliances. These flaws, identified as CVE-2026-59686 through CVE-2026-59690, could enable authenticated attackers to achieve full system compromise, including root access and arbitrary command execution.

Table Of Content

  • Key Takeaways
  • Command Injection Vulnerabilities
  • Broken Access Control Flaws
  • Affected Versions and Patches
  • What You Should Do

The vendor released its advisory on July 27, 2026. Progress has stated that it currently has no evidence of these vulnerabilities being actively exploited in the wild and is unaware of any customer impact. No indicators of compromise have been released at this time.

Command Injection Vulnerabilities

Three of the disclosed vulnerabilities involve operating system command injection, allowing malicious commands to be run on the underlying system.

  • CVE-2026-59686: This vulnerability permits a highly privileged authenticated attacker to execute arbitrary commands directly through the LoadMaster management interface.
  • CVE-2026-59687: Similar to CVE-2026-59686, this flaw presents a command injection risk within the Geo Location management interface.
  • CVE-2026-59688: This command injection issue resides in the backup and restore functionality. An attacker with high administrative privileges could leverage this to execute commands on the appliance’s operating system.

Successful exploitation of any of these command injection vulnerabilities could grant an attacker complete control over the affected appliance, allowing for data manipulation, service disruption, or further network infiltration.

Broken Access Control Flaws

The remaining two vulnerabilities are related to broken access controls, enabling unauthorized privilege escalation or operations.

  • CVE-2026-59689: This is an incorrect authorization flaw that allows a low-privilege authenticated user to escalate their permissions to root. Achieving root access provides an attacker with unrestricted control over the LoadMaster system, including the ability to alter configurations, access sensitive traffic data, establish persistence, or disrupt load-balancing services entirely.
  • CVE-2026-59690: This missing authorization vulnerability affects the REST API. It permits low-privileged authenticated users to perform administrative operations that should be restricted based on their assigned roles. This particular flaw also impacts Progress Kemp Multi-Tenant LoadMaster deployments.

Affected Versions and Patches

The vulnerabilities impact several versions of Progress products:

  • Progress Kemp LoadMaster, Progress ECS Connection Manager, and Progress Connection Manager for ObjectScale versions 7.2.63.27 and earlier.
  • Kemp LoadMaster LTSF version 7.2.54.187 and earlier.
  • For Multi-Tenant LoadMaster, CVE-2026-59690 affects version 7.1.35.157 and earlier.

Progress recommends that all affected organizations update their systems immediately to patched versions. Specific upgrade paths are as follows:

  • LoadMaster GA users should upgrade to version 7.2.63.37.
  • LTSF users should install version 7.2.54.197.
  • ECS Connection Manager and Connection Manager for ObjectScale users should upgrade to version 7.2.63.37.
  • Multi-Tenant LoadMaster customers should transition to version 7.1.35.167.

Administrators can verify their installed LoadMaster version via the web interface (version string in the upper-right corner) or during appliance console startup. Organizations running unsupported releases are advised to upgrade to a supported, fixed version, as older versions may no longer receive essential security patches.

What You Should Do

  • Immediately apply the recommended patches to all affected Progress Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale instances.
  • Review and audit all administrative accounts, eliminating any unnecessary privileged access.
  • Enforce strong password policies and enable multi-factor authentication (MFA) on all management interfaces and APIs where available.
  • Actively monitor management interface and REST API logs for any unusual commands, unauthorized configuration changes, or suspicious activity.
  • If using unsupported versions, plan for an upgrade to a currently supported, patched release to ensure ongoing security updates.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

PortSwigger Introduces Burp AT Agentic AI for Human-Led Web Pentesting

Next Post

Scammers Impersonate ShinyHunters, Blackmail Breach Victims with Fake Webcam Videos

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Progress LoadMaster Flaws Let Attackers Execute Commands, Gain Root Access
July 28, 2026
PortSwigger Introduces Burp AT Agentic AI for Human-Led Web Pentesting
July 28, 2026
Critical FFmpeg Vulnerabilities Let Attackers Corrupt Memory
July 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us