OS Command Injection Flaw in Progress ADC Products
CVE-2026-8037
Key Information:
- Vendor
Progress Software
- Vendor
- CVE Published:
- 4 June 2026
Badges
What is CVE-2026-8037?
CVE-2026-8037 is a critical vulnerability found in Progress Software's ADC products, specifically affecting the LoadMaster appliance. This vulnerability is classified as an OS Command Injection flaw, which allows an unauthenticated attacker to execute arbitrary commands through various API endpoints due to unsanitized input. This means that malicious actors can exploit this security lapse to gain control over the LoadMaster appliance remotely, potentially compromising sensitive data and the integrity of the system. The implications of such unauthorized access can be dire for organizations, as it poses serious threats to data security and system reliability.
Potential impact of CVE-2026-8037
-
Remote Code Execution: The vulnerability enables attackers to execute arbitrary commands on the LoadMaster appliance, allowing them to manipulate the system, deploy malicious software, or disrupt services.
-
Data Breaches: Unauthorized access to affected systems could lead to exposure of sensitive information, resulting in potential data breaches that could have legal, financial, and reputational repercussions for organizations.
-
Operational Disruption: By exploiting this vulnerability, threat actors can cause significant operational disruptions, potentially leading to downtime and loss of functionality in critical services, directly impacting business continuity.
Affected Version(s)
ECS Connections Manager V7.2.60.0
LoadMaster V7.2.60.0
LoadMaster V7.2.45.12
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
Ravie LakshmananJul 01, 2026Vulnerability / Network Security
2 weeks ago
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
eSentire says attacks began June 29 against a CVSS 9.6 OS command injection flaw that enables unauthenticated code execution.
3 weeks ago
Critical Progress Kemp LoadMaster Vulnerability Enables Pre-Auth Remote Code Execution
CVE-2026-8037 lets unauthenticated attackers run commands on Progress Kemp LoadMaster edge appliances, risking enterprise networks.
3 weeks ago

References
EPSS Score
43% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 📈
Vulnerability started trending
- 🟡
Public PoC available
- 👾
Exploit known to exist
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved