logo

Command Injection Alert: High-Severity Flaws Hit LoadMaster & MOVEit WAF

ID: fb8d857a-c333-529b-b99f-726905cec42b

STIX ID: report--fb8d857a-c333-529b-b99f-726905cec42b

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-15

Date Updated: 2026-04-23

Author: Ddos

...
...

Progress Software has released patches for two high-severity UI/API command injection vulnerabilities (CVE-2025-13444 and CVE-2025-13447) in LoadMaster and MOVEit WAF that can lead to remote code execution and full appliance control. The vendor reports no evidence of exploitation to date and provides specific GA/LTSF/multi-tenant upgrade versions while urging administrators to apply updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.