OS Command Injection Flaw in Progress ADC Products
CVE-2026-8037
Key Information:
- Vendor
Progress Software
- Vendor
- CVE Published:
- 4 June 2026
Badges
What is CVE-2026-8037?
CVE-2026-8037 is a critical vulnerability found in Progress Software's ADC products, specifically affecting the LoadMaster appliance. This vulnerability is classified as an OS Command Injection flaw, which allows an unauthenticated attacker to execute arbitrary commands through various API endpoints due to unsanitized input. This means that malicious actors can exploit this security lapse to gain control over the LoadMaster appliance remotely, potentially compromising sensitive data and the integrity of the system. The implications of such unauthorized access can be dire for organizations, as it poses serious threats to data security and system reliability.
Potential impact of CVE-2026-8037
-
Remote Code Execution: The vulnerability enables attackers to execute arbitrary commands on the LoadMaster appliance, allowing them to manipulate the system, deploy malicious software, or disrupt services.
-
Data Breaches: Unauthorized access to affected systems could lead to exposure of sensitive information, resulting in potential data breaches that could have legal, financial, and reputational repercussions for organizations.
-
Operational Disruption: By exploiting this vulnerability, threat actors can cause significant operational disruptions, potentially leading to downtime and loss of functionality in critical services, directly impacting business continuity.
CISA has reported CVE-2026-8037
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-8037 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
ECS Connections Manager V7.2.60.0
LoadMaster V7.2.60.0
LoadMaster V7.2.45.12
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
CISA has added a critical Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog after attackers were observed targeting exposed devices. Tracked as CVE-2026-8037, the flaw affects Progress LoadMaster and Progress ADC products.
5 days ago

CISA Flags Progress LoadMaster Command Injection Vulnerability Exploited in the Wild - IT Security News
2026-08-10 15:08 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability in Progress LoadMaster, tracked as CVE-2026-8037, to its...
5 days ago
Critical Progress LoadMaster flaw now actively exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability.
6 days ago
References
EPSS Score
99% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🦅
CISA Reported
- 📈
Vulnerability started trending
- 🟡
Public PoC available
- 👾
Exploit known to exist
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved