CVE-2026-3518

EUVD-2026-23857
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
ProgressSoftwareCNA
8.4 HIGH
ADJACENT_NETWORK
LOW
HIGH
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
progressloadmaster
7.2.37.0 ≤
𝑥
< 7.2.63.0
CNA
progressloadmaster
7.2.49.0 ≤
𝑥
< 7.2.63.0
CNA
progressloadmaster
7.2.62.0 ≤
𝑥
< 7.2.63.0
CNA