Progress
Progress Loadmaster: vulnerabilidades y CVE
Progress Loadmaster tiene 26 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 3 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses12
Críticas3
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-8037 | Crítica (9.8) | 77% | ⚠ Explotación activa | 4 jun 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in… |
| CVE-2024-1212 | Crítica (9.8) | 95% | ⚠ Explotación activa | 21 feb 2024 | Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-59690 | Alta (8) | 0.26% | — | 27 jul 2026 | A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to… |
| CVE-2026-59689 | Alta (8) | 0.26% | — | 27 jul 2026 | An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate… |
| CVE-2026-59688 | Alta (8.4) | 1.7% | — | 27 jul 2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary… |
| CVE-2026-59687 | Alta (8.4) | 1.7% | — | 27 jul 2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary… |
| CVE-2026-59686 | Alta (8.4) | 1.7% | — | 27 jul 2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary… |
| CVE-2026-8037 | Crítica (9.8) | 77% | ⚠ Explotación activa | 4 jun 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in… |
| CVE-2026-4048 | Alta (7.2) | 4.2% | — | 20 abr 2026 | OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting… |
| CVE-2026-3519 | Alta (7.2) | 4.2% | — | 20 abr 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by… |
| CVE-2026-3518 | Alta (7.2) | 4.2% | — | 20 abr 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting… |
| CVE-2026-3517 | Alta (7.2) | 4.2% | — | 20 abr 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance… |
| CVE-2025-13447 | Media (6.8) | 27% | — | 13 ene 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by… |
| CVE-2025-13444 | Media (6.8) | 27% | — | 13 ene 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by… |
| CVE-2025-1758 | Alta (8.8) | 4.8% | — | 19 mar 2025 | Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above |
| CVE-2024-56135 | Media (6.8) | 0.60% | — | 5 feb 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From… |
| CVE-2024-56134 | Media (6.8) | 0.60% | — | 5 feb 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From… |
| CVE-2024-56133 | Media (6.8) | 0.60% | — | 5 feb 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From… |
| CVE-2024-56132 | Media (6.8) | 6.3% | — | 5 feb 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From… |
| CVE-2024-56131 | Media (6.8) | 6.1% | — | 5 feb 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From… |
| CVE-2024-8755 | Crítica (9.8) | 1.2% | — | 11 oct 2024 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From… |
| CVE-2024-6658 | Media (6.8) | 0.55% | — | 12 sept 2024 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.0 (inclusive) From… |
| CVE-2024-3544 | Alta (7.5) | 0.38% | — | 2 may 2024 | Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to the same network of one of the machines in the HA or Cluster group. This vulnerability has been… |
| CVE-2024-3543 | Alta (7.5) | 0.28% | — | 2 may 2024 | Use of reversible password encryption algorithm allows attackers to decrypt passwords. Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the… |
| CVE-2024-2449 | Alta (7.5) | 13% | — | 22 mar 2024 | A cross-site request forgery vulnerability has been identified in LoadMaster. It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated… |
| CVE-2024-2448 | Alta (8.8) | 55% | — | 22 mar 2024 | An OS command injection vulnerability has been identified in LoadMaster. An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS… |
| CVE-2024-1212 | Crítica (9.8) | 95% | ⚠ Explotación activa | 21 feb 2024 | Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. |
| CVE-2014-5287 | Alta (8.8) | 8.0% | — | 8 ene 2020 | A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI). |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.