Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

LoadMaster — Vulnerabilities & Security Advisories 26

All 26 CVE vulnerabilities found in LoadMaster, with AI-generated Chinese analysis, references, and POCs.

This page provides vulnerability aggregation data for the LoadMaster product line developed by Barracuda Networks, focusing on Common Weakness Enumeration classifications. It compiles a comprehensive list of security flaws affecting this network load balancer platform, covering advisories and reported issues from its initial release through the present day. By accessing this centralized resource, users can systematically track vendor security advisories to stay informed about patch availability and mitigation strategies. Readers are also enabled to gain a deeper understanding of specific weakness classes by analyzing how they manifest within the LoadMaster environment, including impact severity and affected components. Additionally, the page allows for a detailed lookup of the product’s vulnerability history, offering a chronological view of past security incidents and the evolution of the platform’s security posture. This structured approach helps security professionals and system administrators assess risk exposure, prioritize remediation efforts, and maintain compliance with organizational security policies. The data is sourced from official vendor bulletins and recognized security databases to ensure accuracy and reliability. Whether you are evaluating the product for deployment or managing an existing infrastructure, this aggregation serves as a critical reference for understanding the historical and current threat landscape associated with LoadMaster. It consolidates disparate information into a single, accessible format to streamline the vulnerability management process.

Vendor: Progress Software

CVE ID Title CVSS Severity Published
CVE-2026-59690 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API CWE-862 8.0 High 2026-07-27
CVE-2026-59689 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root CWE-863 8.0 High 2026-07-27
CVE-2026-59688 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality CWE-78 8.4 High 2026-07-27
CVE-2026-59687 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface CWE-78 8.4 High 2026-07-27
CVE-2026-59686 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface CWE-78 8.4 High 2026-07-27
CVE-2026-8037 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF CWE-77 9.6 Critical 2026-06-04
CVE-2026-4048 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF CWE-77 8.4 High 2026-04-20
CVE-2026-3519 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF CWE-77 8.4 High 2026-04-20
CVE-2026-3518 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF CWE-77 8.4 High 2026-04-20
CVE-2026-3517 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF CWE-77 8.4 High 2026-04-20
CVE-2025-13447 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster 8.4 High 2026-01-13
CVE-2025-13444 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster 8.4 High 2026-01-13
CVE-2025-1758 Progress LoadMaster 安全漏洞 CWE-121 4.3 Medium 2025-03-19
CVE-2024-56135 Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. CWE-20 8.4 High 2025-02-05
CVE-2024-56134 Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. CWE-20 8.4 High 2025-02-05
CVE-2024-56133 Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. CWE-20 8.4 High 2025-02-05
CVE-2024-56132 Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. CWE-20 8.4 High 2025-02-05
CVE-2024-56131 Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. CWE-20 8.4 High 2025-02-05
CVE-2024-8755 Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. CWE-20 8.4 High 2024-10-11
CVE-2024-6658 Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection. CWE-20 8.4 High 2024-09-12
CVE-2024-7591 Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection CWE-78 10.0 Critical 2024-09-05
CVE-2024-3544 LoadMaster Hardcoded SSH Key CWE-798 7.5 High 2024-05-02
CVE-2024-3543 LoadMaster Reversible Password Encryption Algorithm CWE-257 6.4 Medium 2024-05-02
CVE-2024-2449 LoadMaster Cross-Site Request Forgery (CSRF) CWE-352 7.5 High 2024-03-22
CVE-2024-2448 LoadMaster Command Injection Vulnerability CWE-78 8.4 High 2024-03-22
CVE-2024-1212 LoadMaster Pre-Authenticated OS Command Injection CWE-78 10.0 Critical 2024-02-21

All 26 known CVE vulnerabilities affecting LoadMaster with full Chinese analysis, references, and POCs where available.