Critical severity9.6CISA KEVNVD Advisory· Published Jun 4, 2026· Updated Aug 10, 2026
CVE-2026-8037
CVE-2026-8037
Description
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*Range: <7.2.63.2
- cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*Range: <7.2.63.2
- cpe:2.3:a:progress:moveit_web_application_firewall:*:*:*:*:*:*:*:*Range: <7.2.63.2
cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*range: <7.2.54.18
- (no CPE)
Patches
Vulnerability mechanics
References
4- community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691nvdPatchVendor Advisory
- labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/nvdExploitPatchThird Party Advisory
- www.esentire.com/security-advisories/progress-kemp-loadmaster-vulnerability-targeted-cve-2026-8037nvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
14- CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in AttacksCyber Security News · Aug 10, 2026
- CISA Urges Immediate Patching of Exploited Progress LoadMaster VulnerabilitySecurityWeek · Aug 10, 2026
- Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsThe Hacker News · Aug 8, 2026
- Progress: CVE-2026-8037 Added to CISA KEV Under Active ExploitationVypr Intelligence · Aug 7, 2026
- ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreThe Hacker News · Jul 6, 2026
- 6th July – Threat Intelligence ReportCheck Point Research · Jul 6, 2026
- Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation AttemptsThe Hacker News · Jul 1, 2026
- Critical Progress Kemp LoadMaster Vulnerability Enables Pre-Auth Remote Code ExecutionCyber Security News · Jun 30, 2026
- Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-AuthThe Hacker News · Jun 30, 2026
- Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)watchTowr Labs · Jun 29, 2026
- ZDI-26-341: Progress Software Kemp LoadMaster dolistapikeys Uninitialized Memory Remote Code Execution VulnerabilityZero Day Initiative · Jun 9, 2026
- ZDI-26-340: Progress Software Kemp LoadMaster dodelapikey Uninitialized Memory Remote Code Execution VulnerabilityZero Day Initiative · Jun 9, 2026
- ZDI-26-342: Progress Software Kemp LoadMaster apiuser Uninitialized Memory Remote Code Execution VulnerabilityZero Day Initiative · Jun 9, 2026
- CISA Adds One Known Exploited Vulnerability to CatalogCISA Alerts