CVE-2026-4048Patch(progress / connection_manager_for_objectscale)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch progress connection_manager_for_objectscale systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connection_manager_for_objectscale
  • ecs_connection_manager
  • loadmaster

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
connection_manager_for_objectscaleecs_connection_managerloadmaster

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-22: 1Mentions · 2026-06-02: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-22: 104-2206-02
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-221
Patch1
2026-06-021
Disclosure1
Full discourse2 posts
  • Blue Team News@blueteamsec1
    Disclosure

    MOVEit WAF Critical Security Bulletin – April 2026 – (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048, CVE-2026-21876) http://dlvr.it/TSqvhx #cyber #threathunting #infosec

    Post summary

    The tweet announces a critical security bulletin for MOVEit WAF in April 2026, listing several CVEs.

    00000502
    56.1K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Progress patches multiple critical vulnerabilities in MOVEit WAF and Progress Kemp LoadMaster! This includes CVE-2026-21876 which allows attackers to bypass the WAF! More info: https://community.progress.com/s/article/MOVEit-WAF-Critical-Security-Bulletin-April-2026-CVE-2026-3517-CVE-2026-3518-CVE-2026-3519-CVE-2026-4048-CVE-2026-21876 #patch #patch #patch

    Post summary

    Progress announced patches for several critical MOVEit WAF and Kemp LoadMaster vulnerabilities, including CVE‑2026‑21876, which enables WAF bypass, and directed users to their patch bulletin for updates.

    00000244
    7.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appprogressconnection_manager_for_objectscale---
Appprogressecs_connection_manager---
Appprogressloadmaster---
Appprogressloadmaster---

Explore more