Progress Software's ADC products have critical vulnerabilities that allow authenticated attackers with specific permissions to execute arbitrary commands.
Claims
Progress Software's ADC products have critical vulnerabilities that allow authenticated attackers with specific permissions to execute arbitrary commands.
Parent: CybersecurityEntity: Progress Software ADC ProductsSub-entity: LoadMaster, MOVEit WAFImpact: negativeDate: Apr 20, 2026 - Apr 21, 2026Target: Progress Software's ADC products have critical vulnerabilities that allow authenticated attackers with specific permissions to execute arbitrary commands.
Source posts
π¨ EUVD-2026-23858
π Score: 8.4/10 (CVSS v3.1)
π¦ Product: MOVEit WAF, Object Scale Connection Manager, LoadMaster (+1 more)
π’ Vendor: Progress Software
π
Updated: 2026-04-20
π OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with βVS Administrationβ permissions to execute arbitrary commands o...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23858
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
π¨ EUVD-2026-23857
π Score: 8.4/10 (CVSS v3.1)
π¦ Product: LoadMaster, MOVEit WAF, Object Scale Connection Manager (+1 more)
π’ Vendor: Progress Software
π
Updated: 2026-04-20
π OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with βAllβ permissions to execute arbitrary commands on the LoadMast...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23857
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
π¨ EUVD-2026-23856
π Score: 8.4/10 (CVSS v3.1)
π¦ Product: LoadMaster, ECS Connections Manager, MOVEit WAF (+1 more)
π’ Vendor: Progress Software
π
Updated: 2026-04-20
π OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with βGeo Administrationβ permissions to execute arbitrary commands on the L...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23856
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
π¨ EUVD-2026-23895
π Score: 6.7/10 (CVSS v3.1)
π¦ Product: PowerProtect Data Domain, PowerProtect Data Domain
π’ Vendor: Dell
π
Updated: 2026-04-20
π Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command injection vulnerability. A high privileged attacker with remote acces...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23895
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
π¨ EUVD-2026-23906
π Score: 6.7/10 (CVSS v3.1)
π¦ Product: PowerProtect Data Domain, PowerProtect Data Domain
π’ Vendor: Dell
π
Updated: 2026-04-20
π Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary comman...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23906
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts Β· 0 favs Β· 0 replies Β· Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
π¨ EUVD-2026-24079
π Score: 8.7/10 (CVSS v3.1)
π¦ Product: Router QN-I-470
π’ Vendor: Quantum Networks
π
Updated: 2026-04-21
π This vulnerability exists in Quantum Networks router due to inadequate sanitization of user-supplied input in the management CLI interface. An authenticated remote attacker could exploit this vulnerability by injecting arbitrary OS commands ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24079
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability