CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-08-07. EPSS: 77.4% chance of exploitation in the next 30 days.
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
Affected products
- Progress Connection Manager For Objectscale: before 7.2.63.2 (fixed in 7.2.63.2)
- Progress Ecs Connection Manager: before 7.2.63.2 (fixed in 7.2.63.2)
- Progress LoadMaster: before 7.2.54.18 (fixed in 7.2.54.18); from 7.2.55.0, before 7.2.63.2 (fixed in 7.2.63.2)
- Progress MOVEit Web Application Firewall: before 7.2.63.2 (fixed in 7.2.63.2)
Published 2026-06-04. Last modified 2026-10-01.