Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster
    Cybersecurity

    Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster

    adminBy adminApril 22, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Vulnerability
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Progress Software on Monday rolled out patches for multiple MOVEit WAF and LoadMaster vulnerabilities that could lead to remote code execution (RCE) and OS command injection.

    Two of the bugs, CVE-2026-3517 and CVE-2026-3519, impact APIs in Progress ADC products and could be exploited by users with ‘Geo Administration’ and ‘VS Administration’ permissions for the execution of arbitrary commands on the LoadMaster appliance.

    The flaws exist because the ‘addcountry’ and ‘aclcontrol’ commands do not properly sanitize user-supplied input.

    Another issue, tracked as CVE-2026-3518, impacts an API in the ADC products’ LoadMaster and can be exploited by an authenticated attacker who has the ‘All’ permissions. It exists because the ‘killsession’ command allows unsanitized input.

    The fourth security defect, CVE-2026-4048, impacts the UI in Progress ADC products. An authenticated attacker with the ‘All’ permissions can inject code in a custom WAF rule file, leading to command execution as the input is improperly sanitized during the file upload process.

    On Monday, Progress also announced fixes for CVE-2026-21876, a firewall policy bypass issue in the rule set to flag non-standard character sets used in HTTP multipart request headers.

    Advertisement. Scroll to continue reading.

    The flawed logic leads to character set validation being applied only to the last multipart content type header, even if the application iterates over all headers in the request.

    “This vulnerability allows a specially crafted multipart request to contain an encoded malicious payload that will bypass WAF detection,” Progress explains.

    Successful exploitation of these flaws could allow authenticated attackers to execute arbitrary commands and code on the LoadMaster and MOVEit WAF appliances.

    Progress patched the bugs in MOVEit WAF version 7.2.63.0, LoadMaster GA version 7.2.63.1, LoadMaster LTSF version 7.2.54.17, ECS Connection Manager version 7.2.63.1, and Connection Manager for ObjectScale version 7.2.63.1.

    The company says it has not received any reports that these vulnerabilities have been exploited, but urges customers to update their deployments as soon as possible.

    Related: Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities

    Related: Splunk Enterprise Update Patches Code Execution Vulnerability

    Related: Cisco Patches Critical Vulnerabilities in Webex, ISE

    Related: Two Vulnerabilities Patched in Ivanti Neurons for ITSM

    LoadMaster MOVEit multiple Patches Progress Vulnerabilities WAF
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleHow to build a YouTube analytics report in Data Studio
    Next Article Microsoft releases emergency patches for critical ASP.NET flaw
    admin
    • Website

    Related Posts

    Phishing reclaims the top initial access spot, attackers experiment with AI tools

    April 22, 2026

    Microsoft releases emergency patches for critical ASP.NET flaw

    April 22, 2026

    Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023

    April 22, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Most Pixel owners are ignoring one of the phone’s strangest built-in sensors

    April 22, 2026

    How to Build a WooCommerce Sales Funnel That Converts

    April 22, 2026

    Phishing reclaims the top initial access spot, attackers experiment with AI tools

    April 22, 2026

    What Multi-Location Brands Must Do

    April 22, 2026
    Categories
    • Blogging (67)
    • Cybersecurity (1,443)
    • Privacy & Online Earning (176)
    • SEO & Digital Marketing (877)
    • Tech Tools & Mobile / Apps (1,730)
    • WiFi / Internet & Networking (238)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Most Pixel owners are ignoring one of the phone’s strangest built-in sensors

    April 22, 2026

    How to Build a WooCommerce Sales Funnel That Converts

    April 22, 2026

    Phishing reclaims the top initial access spot, attackers experiment with AI tools

    April 22, 2026
    Most Popular
    • Most Pixel owners are ignoring one of the phone’s strangest built-in sensors
    • How to Build a WooCommerce Sales Funnel That Converts
    • Phishing reclaims the top initial access spot, attackers experiment with AI tools
    • What Multi-Location Brands Must Do
    • Gboard – the Google Keyboard (Wear OS) 5.2.03.872026769 APK Download by Google LLC
    • Microsoft releases emergency patches for critical ASP.NET flaw
    • Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster
    • How to build a YouTube analytics report in Data Studio
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.