CVE-2026-59686: Progress Connection Manager For Objectscale
High severity, CVSS 8.4. EPSS: 1.7% chance of exploitation in the next 30 days.
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.
Affected products
- Progress Connection Manager For Objectscale: before 7.2.63.3 (fixed in 7.2.63.3)
- Progress Ecs Connection Manager: before 7.2.63.3 (fixed in 7.2.63.3)
- Progress LoadMaster: before 7.2.54.19 (fixed in 7.2.54.19); from 7.2.55.0, before 7.2.63.3 (fixed in 7.2.63.3)
- Progress MOVEit Web Application Firewall: before 7.2.63.3 (fixed in 7.2.63.3)
Published 2026-07-27. Last modified 2026-08-11.