CVE-2026-3517: Progress Connection Manager For Objectscale
High severity, CVSS 7.2. EPSS: 3% chance of exploitation in the next 30 days.
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command
Affected products
- Progress Connection Manager For Objectscale: before 7.2.63.1 (fixed in 7.2.63.1)
- Progress Ecs Connection Manager: before 7.2.63.1 (fixed in 7.2.63.1)
- Progress LoadMaster: before 7.2.54.17 (fixed in 7.2.54.17); before 7.2.63.1 (fixed in 7.2.63.1)
Published 2026-04-20. Last modified 2026-06-17.