보안 권고문

Progress Software 제품 보안 업데이트 권고 (CVE-2026-8037)

  • Progress Software가 제품 취약점을 해결하기 위한 보안 업데이트를 발표하였다.
  • 취약점은 Progress ADC 제품의 API에서 발생하는 OS command injection(운영체제 명령 삽입)으로 인한 원격 코드 실행 취약점인 CVE-2026-8037이다.
  • 영향을 받는 제품과 버전은 다음과 같다.
    • Progress Kemp LoadMaster GA 버전 7.2.63.1 이하.
    • Progress Kemp LoadMaster LTSF 버전 7.2.54.17 이하.
    • Progress ECS Connection Manager 버전 7.2.63.1 이하.
    • Progress Connection Manager for ObjectScale 버전 7.2.63.1 이하.
    • Progress MOVEit WAF GA 버전 7.2.63.1 이하.
  • 해당 취약점은 최신 업데이트를 통해 패치가 제공되었다.
  • 업데이트 이후의 안전한 버전은 다음과 같다.
    • Progress Kemp LoadMaster GA 버전 7.2.63.2 이상.
    • Progress Kemp LoadMaster LTSF 버전 7.2.54.18 이상.
    • Progress ECS Connection Manager 버전 7.2.63.2 이상.
    • Progress Connection Manager for ObjectScale 버전 7.2.63.2 이상.
    • Progress MOVEit WAF GA 버전 7.2.63.2 이상.
  • 참고 자료로 LoadMaster Critical Security Bulletin – June 2026 – (CVE-2026-8037, CVE-2026-33691)과 MOVEit WAF Critical Security Bulletin – June 2026 – (CVE-2026-8037, CVE-2026-33691)가 제시되었다.