Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerabilities in LoadMaster Demand Immediate Updates

Critical Vulnerabilities in LoadMaster Demand Immediate Updates

Posted on July 28, 2026 By CWS

Progress has identified five significant vulnerabilities in its Kemp LoadMaster products which could allow attackers to execute commands and gain unauthorized access to critical systems. These issues, impacting several older versions, have prompted urgent security advisories for affected users.

Tracked under identifiers CVE-2026-59686 through CVE-2026-59690, these vulnerabilities could lead to full system compromise if exploited by authenticated users. A security bulletin released on July 27, 2026, emphasized the importance of immediate action, although no active exploitation has been reported so far.

Command Injection Risks

Three of the identified vulnerabilities involve command injection flaws. CVE-2026-59686, for instance, allows attackers with high privileges to execute arbitrary commands via the LoadMaster management interface. Similarly, CVE-2026-59687 and CVE-2026-59688 pose risks through the Geo Location management and backup functionalities, respectively.

These command injection vulnerabilities could enable attackers with administrative access to gain complete control over the affected systems, posing severe risks to the integrity and security of the network infrastructure.

Access Control Weaknesses

The other two vulnerabilities pertain to broken access controls. CVE-2026-59689 allows low-privilege users to escalate their permissions to the root level, granting them extensive control over the system. This includes the ability to modify configurations, access sensitive data, and disrupt services.

Additionally, CVE-2026-59690, affecting the REST API, permits unauthorized privileged operations, which should be restricted according to user roles. This affects not only single deployments but also multi-tenant environments.

Urgent Upgrade Recommendations

The affected versions include Progress Kemp LoadMaster 7.2.63.27 and earlier, along with ECS Connection Manager and Connection Manager for ObjectScale. Users are strongly advised to upgrade to version 7.2.63.37 for GA users and 7.2.54.197 for LTSF users. Multi-Tenant LoadMaster customers should move to version 7.1.35.167.

Organizations still using unsupported versions are at risk and should transition to supported updates to ensure they receive ongoing security patches. Administrators should verify their software version via the web interface or appliance console to confirm compliance.

Given the authentication requirement for these vulnerabilities, enhancing security protocols is crucial. This includes reviewing administrative privileges, enforcing strong passwords, adopting multi-factor authentication, and monitoring system activities for suspicious behavior.

By taking these proactive measures, organizations can safeguard their systems against potential threats and maintain robust cybersecurity defenses.

Cyber Security News Tags:access control, Authentication, command injection, CVE, Cybersecurity, Kemp, LoadMaster, Patch, Progress, REST API, security update, Vulnerabilities

Post navigation

Previous Post: Critical Fastjson Security Flaw Exploited in Attacks
Next Post: Google Introduces New Naming System for Threat Actors

Related Posts

Top 10 Best Digital Footprint Monitoring Tools For Organizations 2025 Top 10 Best Digital Footprint Monitoring Tools For Organizations 2025 Cyber Security News
Apache bRPC Vulnerability Allows Attackers to Crash the Service via Network Apache bRPC Vulnerability Allows Attackers to Crash the Service via Network Cyber Security News
Critical Juniper Networks Flaw Exposes Devices to Attacks Critical Juniper Networks Flaw Exposes Devices to Attacks Cyber Security News
New Malware Strains Increase Threats to Network Devices New Malware Strains Increase Threats to Network Devices Cyber Security News
100+ Cybersecurity Predictions 2026 for Industry Experts as the AI Adapted in the Wild 100+ Cybersecurity Predictions 2026 for Industry Experts as the AI Adapted in the Wild Cyber Security News
JetBrains Fixes Critical TeamCity Vulnerability JetBrains Fixes Critical TeamCity Vulnerability Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SloppyRAT Malware: New Tactics via ClickFix Uncovered
  • Ukrainian Hacker Sentenced for Role in Conti Ransomware
  • IDScan Data Breach: 153M Driver’s Licenses Exposed
  • Kiteworks Enhances Data Security with Bonfy.AI Acquisition
  • Exploitation of Cisco FMC Vulnerabilities Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SloppyRAT Malware: New Tactics via ClickFix Uncovered
  • Ukrainian Hacker Sentenced for Role in Conti Ransomware
  • IDScan Data Breach: 153M Driver’s Licenses Exposed
  • Kiteworks Enhances Data Security with Bonfy.AI Acquisition
  • Exploitation of Cisco FMC Vulnerabilities Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark