OS Command Injection Flaw in Progress ADC Products
CVE-2026-8037

9.6CRITICAL

Key Information:

Badges

📈 Trended📈 Score: 3,610👾 Exploit Exists🟡 Public PoC🟣 EPSS 43%📰 News Worthy

What is CVE-2026-8037?

CVE-2026-8037 is a critical vulnerability found in Progress Software's ADC products, specifically affecting the LoadMaster appliance. This vulnerability is classified as an OS Command Injection flaw, which allows an unauthenticated attacker to execute arbitrary commands through various API endpoints due to unsanitized input. This means that malicious actors can exploit this security lapse to gain control over the LoadMaster appliance remotely, potentially compromising sensitive data and the integrity of the system. The implications of such unauthorized access can be dire for organizations, as it poses serious threats to data security and system reliability.

Potential impact of CVE-2026-8037

  1. Remote Code Execution: The vulnerability enables attackers to execute arbitrary commands on the LoadMaster appliance, allowing them to manipulate the system, deploy malicious software, or disrupt services.

  2. Data Breaches: Unauthorized access to affected systems could lead to exposure of sensitive information, resulting in potential data breaches that could have legal, financial, and reputational repercussions for organizations.

  3. Operational Disruption: By exploiting this vulnerability, threat actors can cause significant operational disruptions, potentially leading to downtime and loss of functionality in critical services, directly impacting business continuity.

Affected Version(s)

ECS Connections Manager V7.2.60.0

LoadMaster V7.2.60.0

LoadMaster V7.2.45.12

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts

Ravie LakshmananJul 01, 2026Vulnerability / Network Security

2 weeks ago

Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts

eSentire says attacks began June 29 against a CVSS 9.6 OS command injection flaw that enables unauthenticated code execution.

3 weeks ago

Critical Progress Kemp LoadMaster Vulnerability Enables Pre-Auth Remote Code Execution

CVE-2026-8037 lets unauthenticated attackers run commands on Progress Kemp LoadMaster edge appliances, risking enterprise networks.

3 weeks ago

References

EPSS Score

43% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 📈

    Vulnerability started trending

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jacky Yang and Syed Ibrahim Ahmed of TrendAI Research
.