← Back to CVE List
CVE-2026-8037NVD
Vulnerability Summary
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
CVSS v3.1 Base Metrics — Score 9.6 (CRITICAL)
Attack VectorAdjacent
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Progress Connection Manager For Objectscale < 7.2.63.2
- Progress Ecs Connection Manager < 7.2.63.2
- Progress Moveit Web Application Firewall < 7.2.63.2
- Progress Loadmaster < 7.2.54.18
- Progress Loadmaster >= 7.2.55.0 and < 7.2.63.2
- Progress Connection Manager For Objectscale 7.2.63.2
- Progress Ecs Connection Manager 7.2.63.2
- Progress Moveit Web Application Firewall 7.2.63.2
- Progress Loadmaster 7.2.54.18
- Progress Loadmaster 7.2.63.2
External References
- https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691
- https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8037
- https://www.esentire.com/security-advisories/progress-kemp-loadmaster-vulnerability-targeted-cve-2026-8037