Progress Software Vulnerabilities and Affected Products
Vulnerabilities associated with ECS Connection Manager.
Products
Clear product- Telerik UI for ASP.NET AJAX17 vulnerabilities
- LoadMaster15 vulnerabilities
- MOVEit WAF10 vulnerabilities
- Object Scale Connection Manager10 vulnerabilities
- Flowmon7 vulnerabilities
- MOVEit Automation6 vulnerabilities
- ECS Connection Manager5 vulnerabilities
- ECS Connections Manager5 vulnerabilities
- Sitefinity5 vulnerabilities
- Telerik Reporting5 vulnerabilities
- Telerik UI for WPF5 vulnerabilities
- Flowmon ADS4 vulnerabilities
- Telerik Report Server3 vulnerabilities
- Chef Automate2 vulnerabilities
- Hybrid Data Pipeline2 vulnerabilities
- Telerik Document Processing Libraries2 vulnerabilities
- Telerik UI for WinForms2 vulnerabilities
- Chef Inspec1 vulnerability
- Kendo UI for Angular1 vulnerability
- Kendo UI for jQuery1 vulnerability
- KendoReact1 vulnerability
- MOVEit Transfer1 vulnerability
- Multi Tenant1 vulnerability
- Multi Tenant LoadMaster1 vulnerability
- Progress® Telerik® Document Processing Libraries1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-59690HIGH | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST APIA Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise. CWE-862Jul 27, 2026 | CVSS8.0v3.1 | EPSS0.175% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-59689HIGH | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to RootAn Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise. CWE-863Jul 27, 2026 | CVSS8.0v3.1 | EPSS0.169% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-59688HIGH | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore FunctionalityAn OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise. CWE-78Jul 27, 2026 | CVSS8.4v3.1 | EPSS0.72% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-59687HIGH | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management InterfaceAn OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise. CWE-78Jul 27, 2026 | CVSS8.4v3.1 | EPSS0.72% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-59686HIGH | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management InterfaceAn OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise. CWE-78Jul 27, 2026 | CVSS8.4v3.1 | EPSS0.738% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |