Vulnerability intelligence
CVE-2026-3517
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command
CVSS Score
8.4
High
EPSS — Exploit Probability
18%
Riskier than 97% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Apr 21, 2026 · latest Apr 21, 2026
Coverage timeline
-
Progress patches MOVEit WAF, LoadMaster command injection flawswww.securityweek.com · Apr 21, 2026