← Back to browse · API

CVE-2026-3518

Severity
HIGH
CVSS
8.4
EPSS
0.1985
Risk score
40.55
CISA KEV
No
PoC
No
Published
2026-04-20
Modified
2026-04-22
First seen
2026-08-07
Aliases
EUVD-2026-23857, GHSA-WVWG-7G9Q-G3V4
Products
Progress Software:ECS Connections Manager V7.2.49.0 <V7.2.63.0, Progress Software:LoadMaster V7.2.37.0 <V7.2.63.0, Progress Software:MOVEit WAF V7.2.62.0 <V7.2.63.0, Progress Software:Object Scale Connection Manager V7.2.62.0 <V7.2.63.0
Sources
euvd EUVD-2026-23857

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command

References