Junglewise Threat Intelligence

CVE-2026-8037: Progress LoadMaster OS command injection in API

CVE-2026-8037 · Severity: critical · CVSS 9.6 · Exploited in the wild · Published 2026-06-04

Technologies: Progress ADC. Vendors: Progress.

Executive brief

Progress LoadMaster is a networking appliance used to balance web traffic and ensure application availability. A critical security flaw allows unauthorized attackers to take complete control of the device by sending malicious requests to its management interface. This could lead to a total service outage, interception of network traffic, or a foothold for further attacks into the corporate network.

Technical details

An OS command injection vulnerability exists in the API of Progress LoadMaster and related ADC products. The flaw stems from improper neutralization of special elements (CWE-77) within multiple command endpoints, where unsanitized user input is passed directly to system shells. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the affected API endpoints. Successful exploitation results in full Remote Code Execution (RCE) with root privileges on the underlying appliance. This vulnerability is confirmed to be exploited in the wild and patches are available in versions 7.2.63.2, 7.2.54.18, and later.

Affected products

  • Progress LoadMaster < 7.2.54.18, 7.2.55.0 < 7.2.63.2
  • Progress ECS Connection Manager < 7.2.63.2
  • Progress Connection Manager for ObjectScale < 7.2.63.2

Timeline

  • 2026-06-04: disclosed: Initial vulnerability tracking began
  • 2026-07-13: patched: NIST analysis and patch information published
  • 2026-08-07: kev added: CISA added to Known Exploited Vulnerabilities catalog
  • 2026-08-07: exploited: Confirmed active exploitation in the wild

Related threats