CVE-2026-3518General(progress / connection_manager_for_objectscale)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch progress connection_manager_for_objectscale systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connection_manager_for_objectscale
  • ecs_connection_manager
  • loadmaster

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-04-22); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
connection_manager_for_objectscaleecs_connection_managerloadmaster

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-24: 1Mentions · 2026-06-02: 1Mentions · 2026-06-04: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-22: 1Technical Details · 2026-06-04: 104-2204-2406-0206-04
Signal classification3 categories
General
250.0%
Patch
125.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-221
Patch1
2026-04-241
General1
2026-06-021
General1
2026-06-041
Disclosure1
Full discourse4 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-318|CVE-2026-3518] Progress Software Kemp LoadMaster ssodomain_killsession Command Injection Remote Code Execution Vulnerability (CVSS 8.8; Credit: Michael Argany of TrendAI Research) https://www.zerodayinitiative.com/advisories/ZDI-26-318/

    Post summary

    The advisory announces a newly disclosed command‑injection RCE vulnerability (CVE‑2026‑3518) in Kemp LoadMaster, providing severity details but no PoC, exploit, or patch information in this excerpt.

    01081848
    5.6K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Progress ❗ CVE-2026-3519 ❗ CVE-2026-3518 ❗ CVE-2026-3517 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-progress-2/ https://t.co/YjYiDtjdwh

    Post summary

    The tweet announces three CVEs affecting Progress products and provides a link for additional information, but offers no further technical or exploitation details.

    00001126
    6.7K followersView on X
  • Blue Team News@blueteamsec1
    General

    MOVEit WAF Critical Security Bulletin – April 2026 – (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048, CVE-2026-21876) http://dlvr.it/TSqvhx #cyber #threathunting #infosec

    Post summary

    The tweet announces a MOVEit WAF security bulletin listing several CVEs but provides no additional details, PoCs, patches, or exploitation evidence.

    00000502
    56.1K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Progress patches multiple critical vulnerabilities in MOVEit WAF and Progress Kemp LoadMaster! This includes CVE-2026-21876 which allows attackers to bypass the WAF! More info: https://community.progress.com/s/article/MOVEit-WAF-Critical-Security-Bulletin-April-2026-CVE-2026-3517-CVE-2026-3518-CVE-2026-3519-CVE-2026-4048-CVE-2026-21876 #patch #patch #patch

    Post summary

    The notice announces that Progress has released patches for several critical MOVEit WAF and Kemp LoadMaster vulnerabilities, including CVE-2026-21876, which permits WAF bypass, and references a community bulletin for details.

    00000244
    7.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appprogressconnection_manager_for_objectscale---
Appprogressecs_connection_manager---
Appprogressloadmaster---
Appprogressloadmaster---

Explore more