CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
Other sources
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8037?
CVE-2026-8037 has a critical severity rating of 9.6.
How do I fix CVE-2026-8037?
To fix CVE-2026-8037, you should apply the latest security patches provided by Progress for the affected products.
What products are affected by CVE-2026-8037?
CVE-2026-8037 affects Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF.
What type of vulnerability is CVE-2026-8037?
CVE-2026-8037 is classified as an OS Command Injection Remote Code Execution vulnerability.
Who can exploit CVE-2026-8037?
CVE-2026-8037 can be exploited by unauthenticated attackers to execute arbitrary commands on the LoadMaster appliance.