Progress has addressed five serious vulnerabilities affecting Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale appliances.
These vulnerabilities, tracked as CVE-2026-59686 through CVE-2026-59690, impact several older product releases and could lead to complete appliance compromise when exploited by authenticated users.
The company released a critical security bulletin on July 27, 2026. Progress stated that it has not received reports of active exploitation and is unaware of any direct operational impact on customers. Currently, no indicators of compromise are available.
Three of the vulnerabilities are related to operating system command injection. CVE-2026-59686 allows a highly privileged authenticated attacker to execute arbitrary commands through the LoadMaster management interface.
Five Progress LoadMaster Vulnerabilities
CVE-2026-59687 affects the Geo Location management interface and poses a similar command injection risk. Additionally, CVE-2026-59688 is a command injection issue in the backup and restore functionality.
An attacker with high administrative privileges could exploit this vulnerability to run commands on the underlying operating system. Successful exploitation of any of these command injection vulnerabilities could grant complete control over the affected appliance.
The other two vulnerabilities involve broken access controls. CVE-2026-59689 is an incorrect authorization flaw that permits a low-privilege authenticated user to escalate their permissions to root.
This level of access would give an attacker unrestricted control over the LoadMaster system, including the ability to alter configurations, access sensitive traffic-related data, deploy persistence mechanisms, or disrupt load-balancing services.
CVE-2026-59690 is a missing authorization vulnerability in the REST API, which allows low-privileged authenticated users to perform privileged administrative operations that should be restricted based on their assigned role. This vulnerability also impacts Progress Kemp Multi-Tenant LoadMaster deployments.
These issues affect Progress Kemp LoadMaster, Progress ECS Connection Manager, and Progress Connection Manager for ObjectScale versions 7.2.63.27, 7.2.63.27, and 7.2.63.2, respectively, and earlier.
Kemp LoadMaster LTSF version 7.2.54.187 and earlier is also vulnerable. For Multi-Tenant LoadMaster, CVE-2026-59690 impacts version 7.1.35.157 and earlier.
Progress recommends that organizations update immediately. LoadMaster GA users should upgrade to version 7.2.63.37, while LTSF users should install version 7.2.54.197.
ECS Connection Manager and Connection Manager for ObjectScale users should upgrade to version 7.2.63.37. Multi-Tenant LoadMaster customers should transition to version 7.1.35.167.
Administrators can verify their installed LoadMaster version through the web interface, where the version string appears in the upper-right corner, or via the appliance console during startup.
Organizations using unsupported releases should upgrade to a supported fixed version, as older versions may no longer receive security patches.
Since the vulnerabilities require authentication, defenders are encouraged to review administrative accounts, eliminate unnecessary privileged access, enforce strong passwords and multi-factor authentication where available, and closely monitor management interface and REST API activity for unusual commands or configuration changes.