🚨SEVERITY: CRITICAL — CVSS 9.6Security Advisory

TL;DR 📌

  • Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
  • Highest CVSS: 9.6 (Critical).
  • Listed in CISA KEV (2026-08-07) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-8037.

What it is

CVE-2026-8037 is a command injection vulnerability in Progress LoadMaster, the vendor’s load balancer/ADC appliance. The flaw sits in multiple command endpoints where input is not properly sanitised before being passed through to the underlying system.