CVE-2026-3517Patch(progress / connection_manager_for_objectscale)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch progress connection_manager_for_objectscale systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connection_manager_for_objectscale
  • ecs_connection_manager
  • loadmaster

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-24); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
connection_manager_for_objectscaleecs_connection_managerloadmaster

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-04-20: 1Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Mentions · 2026-04-24: 2Mentions · 2026-06-02: 1Mentions · 2026-06-04: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-24: 1Technical Details · 2026-06-04: 104-2004-2104-2204-2406-0206-04
Signal classification3 categories
Patch
342.9%
Disclosure
228.6%
General
228.6%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-201
Disclosure1
2026-04-211
Patch1
2026-04-221
Patch1
2026-04-242
General1Patch1
2026-06-021
General1
2026-06-041
Disclosure1
Full discourse7 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-319|CVE-2026-3517] Progress Software Kemp LoadMaster addcountry Command Injection Remote Code Execution Vulnerability (CVSS 8.8; Credit: Michael Argany of TrendAI Research) https://www.zerodayinitiative.com/advisories/ZDI-26-319/

    Post summary

    The post announces CVE-2026-3517, a command‑injection remote code execution flaw in Progress Software Kemp LoadMaster, citing a CVSS score of 8.8 and linking to a Zero Day Initiative advisory.

    01030952
    5.6K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Progress ❗ CVE-2026-3519 ❗ CVE-2026-3518 ❗ CVE-2026-3517 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-progress-2/ https://t.co/YjYiDtjdwh

    Post summary

    The post simply lists three CVEs associated with Progress products and directs readers to an external page for details, without offering any technical, exploit, or mitigation information.

    00001126
    6.7K followersView on X
  • Blue Team News@blueteamsec1
    General

    MOVEit WAF Critical Security Bulletin – April 2026 – (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048, CVE-2026-21876) http://dlvr.it/TSqvhx #cyber #threathunting #infosec

    Post summary

    The bulletin lists five MOVEit WAF CVE identifiers but offers no additional vulnerability or mitigation details.

    00000502
    56.1K followersView on X
  • Riskigy@riskigy
    Patch

    Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster. The defects exploit remote code execution, OS command injection, and WAF detection bypass. Two of the bugs, CVE-2026-3517 and CVE-2026-3519, impact APIs in Progress ADC products. https://www.securityweek.com/progress-patches-multiple-vulnerabilities-in-moveit-waf-loadmaster/ https://t.co/whIku7lRsU

    Post summary

    Progress has released patches for several vulnerabilities in its MOVEit WAF and LoadMaster products, including CVE‑2026‑3517 and CVE‑2026‑3519, which involve remote code execution, OS command injection, and WAF detection bypass.

    00000111
    314 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Progress patches multiple critical vulnerabilities in MOVEit WAF and Progress Kemp LoadMaster! This includes CVE-2026-21876 which allows attackers to bypass the WAF! More info: https://community.progress.com/s/article/MOVEit-WAF-Critical-Security-Bulletin-April-2026-CVE-2026-3517-CVE-2026-3518-CVE-2026-3519-CVE-2026-4048-CVE-2026-21876 #patch #patch #patch

    Post summary

    The post highlights that Progress has released patches for several critical MOVEit WAF vulnerabilities, including CVE-2026-21876 which permits WAF bypass, and directs readers to a community article for more information.

    00000244
    7.2K followersView on X
  • Cyber Netsec IO@NetSecIO
    Patch

    PATCH NOW: Progress Software fixes multiple command injection & WAF bypass flaws in MOVEit WAF and LoadMaster. Vulnerabilities (CVE-2026-3517, etc.) could lead to RCE. Update to the latest versions immediately! 🔒 #Vulnerability #PatchTuesday #MOVEit 🔗 https://cyber.netsecops.io/articles/progress-patches-command-injection-flaws-in-moveit-waf-and-loadmaster/?utm_source=twitter&utm_medium=social&utm_campaign=twitter_auto

    Post summary

    The post announces that Progress Software has patched multiple command injection and WAF bypass vulnerabilities in MOVEit WAF and LoadMaster, including CVE‑2026‑3517, and urges users to update immediately.

    0000059
    42 followersView on X
  • Andre Gironda@AndreGironda
    Disclosure

    CVE-2026-3517 CVE-2026-3519 Progress LoadMaster API flaws enable authenticated OS command injection -- https://cvefeed.io/vuln/detail/CVE-2026-3517 -- https://cvefeed.io/vuln/detail/CVE-2026-3519

    Post summary

    The text announces CVE-2026-3517 and CVE-2026-3519 as OS command injection flaws in Progress LoadMaster's API, providing links to CVE detail pages but no PoC, exploit, patch, or active exploitation information.

    00000137
    3.7K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appprogressconnection_manager_for_objectscale---
Appprogressecs_connection_manager---
Appprogressloadmaster---
Appprogressloadmaster---

Explore more