Vulnerability intelligence
CVE-2026-4048
OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.
CVSS Score
8.4
High
EPSS — Exploit Probability
2.1%
Riskier than 81% of all CVEs · checked 2026-09-09
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Apr 21, 2026 · latest Apr 21, 2026
Coverage timeline
-
Progress patches MOVEit WAF, LoadMaster command injection flawswww.securityweek.com · Apr 21, 2026