ZeroHour

CVE-2026-3518

CVSS 3.1
7.2 high
EPSS
20%p97
Published
()
Modified
Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command

Vendors
progress
Products
connection manager for objectscale, ecs connection manager, loadmaster
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news