« Volver al listado

Progress

Progress Loadmaster: vulnerabilidades y CVE

Progress Loadmaster tiene 26 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 3 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE26
Últimos 12 meses12
Críticas3
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-8037Crítica (9.8)77%⚠ Explotación activa4 jun 2026
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in…
CVE-2024-1212Crítica (9.8)95%⚠ Explotación activa21 feb 2024
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-59690Alta (8)0.26%—27 jul 2026
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to…
CVE-2026-59689Alta (8)0.26%—27 jul 2026
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate…
CVE-2026-59688Alta (8.4)1.7%—27 jul 2026
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary…
CVE-2026-59687Alta (8.4)1.7%—27 jul 2026
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary…
CVE-2026-59686Alta (8.4)1.7%—27 jul 2026
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary…
CVE-2026-8037Crítica (9.8)77%⚠ Explotación activa4 jun 2026
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in…
CVE-2026-4048Alta (7.2)4.2%—20 abr 2026
OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting…
CVE-2026-3519Alta (7.2)4.2%—20 abr 2026
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by…
CVE-2026-3518Alta (7.2)4.2%—20 abr 2026
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting…
CVE-2026-3517Alta (7.2)4.2%—20 abr 2026
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance…
CVE-2025-13447Media (6.8)27%—13 ene 2026
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by…
CVE-2025-13444Media (6.8)27%—13 ene 2026
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by…
CVE-2025-1758Alta (8.8)4.8%—19 mar 2025
Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above
CVE-2024-56135Media (6.8)0.60%—5 feb 2025
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From…
CVE-2024-56134Media (6.8)0.60%—5 feb 2025
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From…
CVE-2024-56133Media (6.8)0.60%—5 feb 2025
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From…
CVE-2024-56132Media (6.8)6.3%—5 feb 2025
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From…
CVE-2024-56131Media (6.8)6.1%—5 feb 2025
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From…
CVE-2024-8755Crítica (9.8)1.2%—11 oct 2024
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From…
CVE-2024-6658Media (6.8)0.55%—12 sept 2024
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.0 (inclusive) From…
CVE-2024-3544Alta (7.5)0.38%—2 may 2024
Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to the same network of one of the machines in the HA or Cluster group. This vulnerability has been…
CVE-2024-3543Alta (7.5)0.28%—2 may 2024
Use of reversible password encryption algorithm allows attackers to decrypt passwords. Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the…
CVE-2024-2449Alta (7.5)13%—22 mar 2024
A cross-site request forgery vulnerability has been identified in LoadMaster. It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated…
CVE-2024-2448Alta (8.8)55%—22 mar 2024
An OS command injection vulnerability has been identified in LoadMaster. An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS…
CVE-2024-1212Crítica (9.8)95%⚠ Explotación activa21 feb 2024
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
CVE-2014-5287Alta (8.8)8.0%—8 ene 2020
A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter9
  2. T1210 Exploitation of Remote Services9
  3. T1190 Exploit Public-Facing Application2
  4. T1068 Exploitation for Privilege Escalation1
  5. T1078 Valid Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Progress