Progress Security Updates – 21 April 2026

Progress has released security updates to fix multiple vulnerabilities across several Progress products.

The addressed vulnerabilities could allow the attacker to execute arbitrary commands and gain access to the affected systems.

Sample of the addressed vulnerabilities:

Progress LoadMaster and MOVEit WAF OS Command Injection Remote Code Execution Vulnerability (CVE-2026-3517):

  • CVSS: 8.4
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Gain Access

The affected products:

  • Progress Kemp LoadMaster: GA v7.2.62.2 and older.
  • Progress Kemp LoadMaster: LTSF v7.2.54.16 and older.
  • Progress MOVEit WAF: GA v7.2.62.2 and older.
Vulnerabilities
  • CVE-2026-3517
  • CVE-2026-3518
  • CVE-2026-3519
  • CVE-2026-4048
  • CVE-2026-21876
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Progress Security Advisory

References