VendorsProgressmoveit_web_application_firewallany version
Vulnerabilities

Progress MOVEit Web Application Firewall (WAF) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-8037
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Published 2026-06-04 · Analyzed
9.8KEVEPSS 0.996
CVE-2026-59686
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface
Published 2026-07-27 · Analyzed
8.4EPSS 0.014
CVE-2026-59687
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface
Published 2026-07-27 · Analyzed
8.4EPSS 0.007
CVE-2026-59688
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality
Published 2026-07-27 · Analyzed
8.4EPSS 0.007
CVE-2026-59690
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API
Published 2026-07-27 · Analyzed
8.0EPSS 0.002
CVE-2026-59689
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root
Published 2026-07-27 · Analyzed
8.0EPSS 0.002