OS Command Injection Flaw in Progress ADC Products
CVE-2026-8037

9.6CRITICAL

Key Information:

Badges

📈 Trended📈 Score: 3,610👾 Exploit Exists🟡 Public PoC🟣 EPSS 99%🦅 CISA Reported📰 News Worthy

What is CVE-2026-8037?

CVE-2026-8037 is a critical vulnerability found in Progress Software's ADC products, specifically affecting the LoadMaster appliance. This vulnerability is classified as an OS Command Injection flaw, which allows an unauthenticated attacker to execute arbitrary commands through various API endpoints due to unsanitized input. This means that malicious actors can exploit this security lapse to gain control over the LoadMaster appliance remotely, potentially compromising sensitive data and the integrity of the system. The implications of such unauthorized access can be dire for organizations, as it poses serious threats to data security and system reliability.

Potential impact of CVE-2026-8037

  1. Remote Code Execution: The vulnerability enables attackers to execute arbitrary commands on the LoadMaster appliance, allowing them to manipulate the system, deploy malicious software, or disrupt services.

  2. Data Breaches: Unauthorized access to affected systems could lead to exposure of sensitive information, resulting in potential data breaches that could have legal, financial, and reputational repercussions for organizations.

  3. Operational Disruption: By exploiting this vulnerability, threat actors can cause significant operational disruptions, potentially leading to downtime and loss of functionality in critical services, directly impacting business continuity.

CISA has reported CVE-2026-8037

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-8037 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

ECS Connections Manager V7.2.60.0

LoadMaster V7.2.60.0

LoadMaster V7.2.45.12

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks

CISA has added a critical Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog after attackers were observed targeting exposed devices. Tracked as CVE-2026-8037, the flaw affects Progress LoadMaster and Progress ADC products.

5 days ago

CISA Flags Progress LoadMaster Command Injection Vulnerability Exploited in the Wild - IT Security News

2026-08-10 15:08 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability in Progress LoadMaster, tracked as CVE-2026-8037, to its...

5 days ago

Critical Progress LoadMaster flaw now actively exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability.

6 days ago

References

EPSS Score

99% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 🦅

    CISA Reported

  • 📈

    Vulnerability started trending

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jacky Yang and Syed Ibrahim Ahmed of TrendAI Research
.