TL;DR
Progress fixed five Kemp LoadMaster vulnerabilities in a July 2026 bulletin. Three allow OS command injection, and two allow privilege escalation. Each one can lead to full system compromise on the affected appliance.
- Total: 5 CVEs
- Severity: 5 High
- Actively exploited: None confirmed
- Highest severity: 8.4 (High · CVSSv3) — CVE-2026-59686
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-59686 | 8.4 | CWE-78 | 7.2.63.3, 7.2.54.19 | Not exploited |
| CVE-2026-59687 | 8.4 | CWE-78 | 7.2.63.3, 7.2.54.19 | Not exploited |
| CVE-2026-59688 | 8.4 | CWE-78 | 7.2.63.3, 7.2.54.19 | Not exploited |
| CVE-2026-59689 | 8 | CWE-863 | 7.2.63.3, 7.2.54.19 | Not exploited |
| CVE-2026-59690 | 8 | CWE-862 | 7.2.63.3, 7.2.54.19, 7.1.35.16 | Not exploited |
Why it matters
LoadMaster sits at the network edge and balances enterprise traffic. Therefore, a compromised appliance hands attackers a strong foothold. From there, an intruder can pivot deeper into internal systems. These Kemp LoadMaster vulnerabilities each end in full system takeover. Even so, all five need an authenticated account, which limits remote drive-by attacks. The product also carries a heavy exploitation history, so defenders should treat every advisory seriously.
How the attacks work
Command injection (CVE-2026-59686, 59687, 59688)
A high-privilege user reaches three separate management functions. Each one passes unsanitized input into an operating system command. As a result, the attacker runs arbitrary commands on the appliance. The affected paths include the main interface, the Geo Location feature, and backup restore.
Privilege escalation (CVE-2026-59689, 59690)
A low-privilege user abuses weak authorization checks. One flaw lets that user climb to root. The other exposes privileged REST API actions that the role should block. Both grant an ordinary account administrative power.
Affected versions
The flaws hit LoadMaster GA v7.2.63.2 and earlier. LTSF builds v7.2.54.18 and earlier are also affected. Multi-Tenant LoadMaster v7.1.35.15 and earlier faces CVE-2026-59690 only.
Patch and mitigation
Progress released fixed builds and urges an immediate upgrade. Move GA and ECS to v7.2.63.3, LTSF to v7.2.54.19, and Multi-Tenant to v7.1.35.16. The vendor reports no exploitation and no public proof-of-concept so far. Full details appear in the official Progress security bulletin. Until you patch, restrict management and API access to trusted networks. In addition, review admin accounts and remove any unused high-privilege roles.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.