← All reports

Progress Software's ADC products have critical vulnerabilities that allow authenticated attackers with specific permissions to execute arbitrary commands.

CybersecurityTechnologyConflictInformation SecurityApr 20, 2026score 0.173 posts Β· 0 replies across 1 instances
The thread discusses multiple vulnerabilities in Progress Software's ADC products, specifically OS Command Injection Remote Code Execution Vulnerabilities in their LoadMaster, MOVEit WAF, and other related products. These vulnerabilities allow authenticated attackers with specific permissions to execute arbitrary commands, posing a significant security risk.

Claims

Progress Software's ADC products have critical vulnerabilities that allow authenticated attackers with specific permissions to execute arbitrary commands.
Parent: CybersecurityEntity: Progress Software ADC ProductsSub-entity: LoadMaster, MOVEit WAFImpact: negativeDate: Apr 20, 2026 - Apr 21, 2026Target: Progress Software's ADC products have critical vulnerabilities that allow authenticated attackers with specific permissions to execute arbitrary commands.

Source posts

@[email protected]
🚨 EUVD-2026-23858 πŸ“Š Score: 8.4/10 (CVSS v3.1) πŸ“¦ Product: MOVEit WAF, Object Scale Connection Manager, LoadMaster (+1 more) 🏒 Vendor: Progress Software πŸ“… Updated: 2026-04-20 πŸ“ OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with β€œVS Administration” permissions to execute arbitrary commands o... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23858 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-23857 πŸ“Š Score: 8.4/10 (CVSS v3.1) πŸ“¦ Product: LoadMaster, MOVEit WAF, Object Scale Connection Manager (+1 more) 🏒 Vendor: Progress Software πŸ“… Updated: 2026-04-20 πŸ“ OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with β€œAll” permissions to execute arbitrary commands on the LoadMast... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23857 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-23856 πŸ“Š Score: 8.4/10 (CVSS v3.1) πŸ“¦ Product: LoadMaster, ECS Connections Manager, MOVEit WAF (+1 more) 🏒 Vendor: Progress Software πŸ“… Updated: 2026-04-20 πŸ“ OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with β€œGeo Administration” permissions to execute arbitrary commands on the L... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23856 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-23895 πŸ“Š Score: 6.7/10 (CVSS v3.1) πŸ“¦ Product: PowerProtect Data Domain, PowerProtect Data Domain 🏒 Vendor: Dell πŸ“… Updated: 2026-04-20 πŸ“ Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command injection vulnerability. A high privileged attacker with remote acces... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23895 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-23906 πŸ“Š Score: 6.7/10 (CVSS v3.1) πŸ“¦ Product: PowerProtect Data Domain, PowerProtect Data Domain 🏒 Vendor: Dell πŸ“… Updated: 2026-04-20 πŸ“ Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary comman... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23906 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts Β· 0 favs Β· 0 replies Β· Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-24079 πŸ“Š Score: 8.7/10 (CVSS v3.1) πŸ“¦ Product: Router QN-I-470 🏒 Vendor: Quantum Networks πŸ“… Updated: 2026-04-21 πŸ“ This vulnerability exists in Quantum Networks router due to inadequate sanitization of user-supplied input in the management CLI interface. An authenticated remote attacker could exploit this vulnerability by injecting arbitrary OS commands ... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24079 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability