LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 7, 2026
CVSS 9.6 · Critical⚠ Actively exploited (CISA KEV)
9.6
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Aug 10, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog on Aug 7, 2026, with a federal patch deadline of Aug 10, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

CVE-2026-8037 is a command injection vulnerability in Progress LoadMaster that lets an unauthenticated attacker run arbitrary commands on the appliance by abusing unsanitized input in multiple command endpoints. LoadMaster appliances often sit at the edge of networks as load balancers and application delivery controllers, so successful abuse can give an attacker a foothold on infrastructure that handles traffic for many internal services.

Defenders should treat this as a high-priority edge-device issue: confirm exposure, apply the vendor fix, and watch for signs of misuse until systems are updated. Specifics such as exact fixed versions and any configuration prerequisites must be confirmed against the vendor advisory.

How it works

The weakness is CWE-77 (Improper Neutralization of Special Elements used in a Command). In products of this class, management or API endpoints accept parameters that are later passed into operating-system commands. When those parameters are not properly sanitized or constrained, an attacker can inject shell metacharacters or additional command fragments so that the appliance executes attacker-chosen commands with the privileges of the service handling the request.

According to the CISA summary, an unauthenticated attacker can reach multiple command endpoints on LoadMaster and supply crafted input that is not sanitized before use. That leads to arbitrary command execution on the appliance itself. Public detail beyond that description is limited; do not assume particular payloads, authentication bypass steps, or post-exploitation behavior without verifying them in the vendor advisory and your own testing in a lab.

Am I affected? How to find it in your systems

Progress LoadMaster is typically deployed as a hardware or virtual appliance that terminates or balances HTTP/HTTPS and other application traffic, often in DMZs or at network perimeters. Inventory every instance—physical, virtual, and cloud-hosted—by reviewing asset management records, hypervisor inventories, network management tools, and configuration-management databases for LoadMaster hostnames, management IPs, and product banners.

Absence of obvious log evidence does not prove safety; limited logging on appliances can hide exploitation. Confirm scope and version status directly against the vendor advisory.

How to remediate

Patch first. Apply the vendor-supplied update for Progress LoadMaster that addresses CVE-2026-8037, following Progress’s installation and verification instructions. CISA’s required action is to apply mitigations in accordance with vendor instructions, ensure compliance with BOD 26-04 prioritization guidance, and follow CISA’s forensics triage requirements where applicable. For cloud-delivered or managed instances, follow the BOD 26-04 guidance for cloud services or discontinue use if mitigations are unavailable.

If you can't patch immediately

Until the vendor update is installed, reduce exposure with compensating controls appropriate to command-injection risk on an edge appliance.

These steps lower likelihood and impact but do not replace the patch. Schedule the official update as soon as practicable.

If your data may have been exposed

Actively exploited vulnerabilities on internet-facing appliances can lead to full compromise of the device and subsequent movement into connected environments. Known ransomware use of this CVE is not documented, but that does not rule out other malicious activity. If you suspect exploitation, isolate the appliance, preserve logs and forensic images per your incident response process and CISA’s forensics triage expectations, rotate credentials that may have been handled by the device, and review downstream systems for follow-on access. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior dumps while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedProgress · LoadMaster
WeaknessCWE-77
CVSS base score9.6 (Critical)
CVSS vectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
PublishedJun 4, 2026
Added to CISA KEVAug 7, 2026
Federal patch deadlineAug 10, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities