SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-3519

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in…

HIGH 7.2EPSS 2.13%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
2.13% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-77
Affected
progress/connection manager for objectscale · progress/ecs connection manager · progress/loadmaster
Source
security@progress.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.