A vulnerability was found in Progress Software ECS Connection Manager, LoadMaster, MOVEit WAF and Object Scale Connection Manager. It has been declared as very critical. Impacted is an unknown function of the component Geo Location Management Interface. Executing a manipulation can lead to os command injection.

This vulnerability is registered as CVE-2026-59687. It is possible to launch the attack remotely. No exploit is available.