CVE-2026-3519Disclosure(progress / connection_manager_for_objectscale)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch progress connection_manager_for_objectscale systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connection_manager_for_objectscale
  • ecs_connection_manager
  • loadmaster

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-24); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
connection_manager_for_objectscaleecs_connection_managerloadmaster

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-20: 1Mentions · 2026-04-22: 1Mentions · 2026-04-24: 2Mentions · 2026-06-02: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-24: 104-2004-2204-2406-02
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-201
Disclosure1
2026-04-221
Patch1
2026-04-242
General1Patch1
2026-06-021
Disclosure1
Full discourse5 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Progress ❗ CVE-2026-3519 ❗ CVE-2026-3518 ❗ CVE-2026-3517 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-progress-2/ https://t.co/YjYiDtjdwh

    Post summary

    The post lists three CVEs for Progress products and supplies a link for additional information, but it contains no technical details, patch info, or evidence of exploitation.

    00001126
    6.7K followersView on X
  • Blue Team News@blueteamsec1
    Disclosure

    MOVEit WAF Critical Security Bulletin – April 2026 – (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048, CVE-2026-21876) http://dlvr.it/TSqvhx #cyber #threathunting #infosec

    Post summary

    A security bulletin announces several CVEs for MOVEit WAF, but the provided text offers no additional technical, exploitation, or mitigation information.

    00000502
    56.1K followersView on X
  • Riskigy@riskigy
    Patch

    Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster. The defects exploit remote code execution, OS command injection, and WAF detection bypass. Two of the bugs, CVE-2026-3517 and CVE-2026-3519, impact APIs in Progress ADC products. https://www.securityweek.com/progress-patches-multiple-vulnerabilities-in-moveit-waf-loadmaster/ https://t.co/whIku7lRsU

    Post summary

    Progress released patches for multiple MOVEit WAF and LoadMaster vulnerabilities (CVE-2026-3517, CVE-2026-3519) affecting APIs with remote code execution, OS command injection, and WAF detection bypass.

    00000111
    314 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Progress patches multiple critical vulnerabilities in MOVEit WAF and Progress Kemp LoadMaster! This includes CVE-2026-21876 which allows attackers to bypass the WAF! More info: https://community.progress.com/s/article/MOVEit-WAF-Critical-Security-Bulletin-April-2026-CVE-2026-3517-CVE-2026-3518-CVE-2026-3519-CVE-2026-4048-CVE-2026-21876 #patch #patch #patch

    Post summary

    Progress has released patches for several critical MOVEit WAF vulnerabilities, including CVE-2026-21876 which enables WAF bypass, with details available at the provided link.

    00000244
    7.2K followersView on X
  • Andre Gironda@AndreGironda
    Disclosure

    CVE-2026-3517 CVE-2026-3519 Progress LoadMaster API flaws enable authenticated OS command injection -- https://cvefeed.io/vuln/detail/CVE-2026-3517 -- https://cvefeed.io/vuln/detail/CVE-2026-3519

    Post summary

    The post announces that Progress LoadMaster API flaws CVE-2026-3517 and CVE-2026-3519 allow authenticated users to execute OS command injection.

    00000137
    3.7K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appprogressconnection_manager_for_objectscale---
Appprogressecs_connection_manager---
Appprogressloadmaster---
Appprogressloadmaster---

Explore more