Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster
    Cybersecurity

    Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster

    adminBy adminApril 22, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Vulnerability
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Progress Software on Monday rolled out patches for multiple MOVEit WAF and LoadMaster vulnerabilities that could lead to remote code execution (RCE) and OS command injection.

    Two of the bugs, CVE-2026-3517 and CVE-2026-3519, impact APIs in Progress ADC products and could be exploited by users with ‘Geo Administration’ and ‘VS Administration’ permissions for the execution of arbitrary commands on the LoadMaster appliance.

    The flaws exist because the ‘addcountry’ and ‘aclcontrol’ commands do not properly sanitize user-supplied input.

    Another issue, tracked as CVE-2026-3518, impacts an API in the ADC products’ LoadMaster and can be exploited by an authenticated attacker who has the ‘All’ permissions. It exists because the ‘killsession’ command allows unsanitized input.

    The fourth security defect, CVE-2026-4048, impacts the UI in Progress ADC products. An authenticated attacker with the ‘All’ permissions can inject code in a custom WAF rule file, leading to command execution as the input is improperly sanitized during the file upload process.

    On Monday, Progress also announced fixes for CVE-2026-21876, a firewall policy bypass issue in the rule set to flag non-standard character sets used in HTTP multipart request headers.

    Advertisement. Scroll to continue reading.

    The flawed logic leads to character set validation being applied only to the last multipart content type header, even if the application iterates over all headers in the request.

    “This vulnerability allows a specially crafted multipart request to contain an encoded malicious payload that will bypass WAF detection,” Progress explains.

    Successful exploitation of these flaws could allow authenticated attackers to execute arbitrary commands and code on the LoadMaster and MOVEit WAF appliances.

    Progress patched the bugs in MOVEit WAF version 7.2.63.0, LoadMaster GA version 7.2.63.1, LoadMaster LTSF version 7.2.54.17, ECS Connection Manager version 7.2.63.1, and Connection Manager for ObjectScale version 7.2.63.1.

    The company says it has not received any reports that these vulnerabilities have been exploited, but urges customers to update their deployments as soon as possible.

    Related: Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities

    Related: Splunk Enterprise Update Patches Code Execution Vulnerability

    Related: Cisco Patches Critical Vulnerabilities in Webex, ISE

    Related: Two Vulnerabilities Patched in Ivanti Neurons for ITSM

    LoadMaster MOVEit multiple Patches Progress Vulnerabilities WAF
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleHow to build a YouTube analytics report in Data Studio
    Next Article Microsoft releases emergency patches for critical ASP.NET flaw
    admin
    • Website

    Related Posts

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026

    GitHub confirms breach of 3,800 repos via malicious VSCode extension

    May 20, 2026

    Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google CEO Sundar Pichai Is OK With AI Mode Replacing Classic Search

    June 6, 2026

    Your Next AI Visitor Will Know Who Sent It

    June 6, 2026

    Google Gives Sites AI Search Opt-Out, But Not The Data To Use It

    June 6, 2026

    Why users outsource decisions to AI

    June 6, 2026
    Categories
    • Blogging (90)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (242)
    • SEO & Digital Marketing (1,398)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (336)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google CEO Sundar Pichai Is OK With AI Mode Replacing Classic Search

    June 6, 2026

    Your Next AI Visitor Will Know Who Sent It

    June 6, 2026

    Google Gives Sites AI Search Opt-Out, But Not The Data To Use It

    June 6, 2026
    Most Popular
    • Google CEO Sundar Pichai Is OK With AI Mode Replacing Classic Search
    • Your Next AI Visitor Will Know Who Sent It
    • Google Gives Sites AI Search Opt-Out, But Not The Data To Use It
    • Why users outsource decisions to AI
    • Google’s Updated Guidance Urges FTC Complaints Against Shady SEOs
    • 4 ways to track AI search visibility when attribution falls short
    • Google’s Sergey Brin Sees A Path To AGI But Not Beyond It
    • Bots now make up 57% of webpage requests
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.