Status: EPSS-IMMINENT | Advisory ID: CVE-2026-3518
| CVE | CVE-2026-3518 |
| CVSS | CVSS 8.4 (High). |
| Affected products | Progress LoadMaster, Progress Connection Manager for ObjectScale, and Progress ECS Connection Manager |
| Classified as | CWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection')) |
| Exploitation prediction (EPSS) | 17% probability of exploitation in the next 30 days (97% percentile) -- FIRST.org's EPSS model. |
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with βAllβ permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command