CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-08-07. EPSS: 77.4% chance of exploitation in the next 30 days.

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Affected products

  • Progress Connection Manager For Objectscale: before 7.2.63.2 (fixed in 7.2.63.2)
  • Progress Ecs Connection Manager: before 7.2.63.2 (fixed in 7.2.63.2)
  • Progress LoadMaster: before 7.2.54.18 (fixed in 7.2.54.18); from 7.2.55.0, before 7.2.63.2 (fixed in 7.2.63.2)
  • Progress MOVEit Web Application Firewall: before 7.2.63.2 (fixed in 7.2.63.2)

Published 2026-06-04. Last modified 2026-10-01.