CVE-2026-8037

Published Jun 4, 2026

Last updated 6 days ago

Overview

Description
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
Source
security@progress.com
NVD status
Analyzed
Products
connection_manager_for_objectscale, ecs_connection_manager, moveit_web_application_firewall, loadmaster

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Progress LoadMaster Command Injection Vulnerability
Exploit added on
Aug 7, 2026
Exploit action due
Aug 10, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

security@progress.com
CWE-77

Social media

Hype score
Not currently trending
  1. 🚨 NUEVA CVE: CVE-2026-8037 — Progress LoadMaster (OS Command Injection) ⚠️ CVSS 9.8 (CRÍTICO) · KEV 07/08/2026 · explotación activa Afectados: Appliances Progress LoadMaster (ADC) expostos à int https://t.co/xSps85mJUI

    @Douglas01284182

    13 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 NOVA CVE: CVE-2026-8037 — Progress LoadMaster (OS Command Injection) ⚠️ CVSS 9.8 (CRÍTICO) · KEV 07/08/2026 · exploração ativa Afetados: Appliances Progress LoadMaster (ADC) expostos à interne https://t.co/KQk0wZasEz

    @Douglas01284182

    13 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 NEW CVE: CVE-2026-8037 — Progress LoadMaster (OS Command Injection) ⚠️ CVSS 9.8 (CRITICAL) · KEV 07/08/2026 · active exploitation Affected: Appliances Progress LoadMaster (ADC) expostos à inte https://t.co/sNEMSTTaC1

    @Douglas01284182

    13 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CISA’s Aug. 10 deadlines for exploited LoadMaster CVE-2026-8037 and FortiOS CVE-2025-68686 have passed. Any exception now needs owner escalation, a fixed remediation date, and compromise assessment—not a version check alone. https://t.co/QIjjY5STN3

    @isectech_

    11 Aug 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CISA added 3 NEW exploited CVEs this week. If your team runs any of these, patch today: • Progress LoadMaster (CVE-2026-8037, CVSS 9.8) • JetBrains TeamCity (CVE-2026-63077) • N-able N-central (CVE-2026-18577) https://t.co/JKBcwI6eWs

    @FaultSignal_

    10 Aug 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 Vulnerabilities added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog with patch deadlines: 🔵 Progress LoadMaster (CVE-2026-8037): Command injection flaw → Due Aug 10, 2026 🔵 JetBrains TeamCity (CVE-2026-63077): Deserialization bug → Due Aug 8, 2026

    @techepages

    10 Aug 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CISA adds command injection flaw CVE-2026-8037 in Progress Kemp LoadMaster to the KEV catalog after confirmed in-the-wild exploitation. The unauthenticated vulnerability allows arbitrary command execution because input sanitization is missing. Federal agencies were given a

    @WorldCyberNewsX

    10 Aug 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Progress LoadMaster CVE-2026-8037 Added to CISA KEV Catalog — CISA has added CVE-2026-8037, a Progress LoadMaster command injection vulnerability, to its… https://t.co/2vY0Ed48uj #Cybersecurity #SecOps #VulnerabilityManagement

    @VettedSecOps

    9 Aug 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CISA Warns: Critical Progress LoadMaster RCE Vulnerability (CVE-2026-8037) Actively Exploited CISA has added CVE-2026-8037, a critical pre-auth RCE vulnerability in Progress Kemp LoadMaster, to its Known Exp… https://t.co/PcrF5ysu39 #ThreatIntel #RCE #ActivelyExploited #CVE h

    @BytesNora

    9 Aug 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Recent critical flaws: Progress LoadMaster (CVE-2026-8037) & N-able N-central (CVE-2026-18577) enable RCE/account takeover. TP-Link Omada zero-day vulnerabilities compromise encrypted comms & data privacy. Immediate patching is vital. #Cybersecurity #NetworkSecurity #Zero

    @YourAnon_irc

    9 Aug 2026

    62 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  11. 🔒 #CyberSecurity CVE-2026-8037: Progress Kemp LoadMaster Command Injection Under Active Exploita… "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8037,…" 🔗 https://t.co/xLLAItQKvd #CyberSecurity #ThreatIntel #cve #zeroday #patcht

    @SecurityAr58409

    8 Aug 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🔒 #CyberSecurity CVE-2026-8037: Progress LoadMaster Command Injection Under Active Exploitation … "On August 7, 2026, CISA added CVE-2026-8037 — a command injection vulnerability in…" 🔗 https://t.co/PPmjE5Oopn #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesda

    @SecurityAr58409

    8 Aug 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🔒 #CyberSecurity CVE-2026-8037: Progress LoadMaster Unauthenticated Command Injection — KEV-List… "On August 7, 2026, CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/vD9fYTndEY #CyberSecurity #ThreatIntel #cve20268037 #critical #ci

    @SecurityAr58409

    8 Aug 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Cyber Heat Radar|2026/08/08 05:00 JST 今回は①CVE-2026-63077 CISA KEV追加の件、②CVE-2026-8037 CISA KEV追加の件、③AI分散下のランサムウェア増加の件を中心に、音声で3件扱います。

    @cyberheatradar

    7 Aug 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CVE-2026-8037 looks likely to be weaponised soon. OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker t… EPSS 85% · CVSS 9.6 · Risk 49/100. Good candidate to fix this week. https://t.co/9aI59PSHlZ #CVE

    @BytesNora

    31 Jul 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 13:58 UTC: CVE-2026-8037 disclosed. 🚨 ALERT - Attackers are trying to exploit CVE-2026-8037 in Progress Kemp LoadMaster. The CVSS 9.6 flaw enables unauthe

    @lyrie_ai

    21 Jul 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. CVE-2026-8037: ⚠️ Public PoC is out for CVE-2026-8037, a critical Progress Kemp LoadMaster API flaw. It lets unauthenticated attackers run root commands when the API is enabled. Patch now. Restrict API exposure. Full story:

    @lyrie_ai

    19 Jul 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  18. ⚠️ Vulnerabilidad en productos Progress ❗ CVE-2026-8037 ❗ CVE-2026-33691 ➡️ Más info: https://t.co/pHWOxl9bky https://t.co/4dzHP34ERB

    @CERTpy

    13 Jul 2026

    201 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🚨 CVE-2026-8037 - critical 🚨 Progress ADC LoadMaster - Command Injection > OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Produ... 👾 https://t.co/jsn1droBuB @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    4 Jul 2026

    249 Impressions

    1 Retweet

    1 Like

    2 Bookmarks

    0 Replies

    0 Quotes

  20. Legacy exposure keeps paying off for attackers. Progress Kemp LoadMaster CVE-2026-8037 exploitation moves… Attackers are targeting CVE-2026-8037, a critical pre-auth command injection flaw in Progre… 🔗 Read → https://t.co/FpD8k42ZQl

    @fynn_JourX

    2 Jul 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. For defenders, progress kemp loadmaster cve-2026-8037 exploitation moves fast… should move fast. Attackers are targeting CVE-2026-8037, a critical pre-auth command injection flaw in Progre… 🔗 Details → https://t.co/XoROy1dKFI

    @SocXAInvaders

    2 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. ⚠️ Vulnerabilidad en productos Progress ❗ CVE-2026-8037 ❗ CVE-2026-33691 ➡️ Más info: https://t.co/SPwHWmm3cm https://t.co/JlAMWbyS2X

    @CERTpy

    19 Jun 2026

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 【Progress Kemp LoadMasterに未認証RCE脆弱性】 Progress Kemp LoadMasterに、CVE-2026-8037とCVE-2026-33691の2件の脆弱性が公表されました。CVE-2026-8037はAPIの入力検証不備に起因するOSコマンドインジェクションで、認証なしに任

    @01ra66it

    7 Jun 2026

    327 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Progress issued a LoadMaster security bulletin on two flaws CVE-2026-8037 and CVE-2026-33691 disclosed in June 2026, according to Canada's Cyber Centre. https://t.co/NOPtr7ylqT

    @threatcluster

    6 Jun 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations