All CVEs
Vulnerability intelligence

CVE-2026-3517

Progress Software LoadMaster CWE-77

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command

CVSS Score
8.4
High
EPSS — Exploit Probability
18%
Riskier than 97% of all CVEs · checked 2026-09-09
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Apr 21, 2026 · latest Apr 21, 2026

Coverage timeline

Related CVEs — Progress Software