Progress LoadMaster: API Cmd Injection RCE in Multiple Endpoints
CVE-2026-8037 Published on June 4, 2026
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
Known Exploited Vulnerability
This Progress LoadMaster Command Injection Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
The following remediation steps are recommended / required by August 10, 2026: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicab
Vulnerability Analysis
Weakness Type
What is a Command Injection Vulnerability?
The software constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVE-2026-8037 has been classified to as a Command Injection vulnerability or weakness.
Affected Versions
Progress Software LoadMaster:- Version V7.2.60.0 and below V7.2.63.2 is affected.
- Version V7.2.45.12 and below V7.2.54.18 is affected.
- Version V7.2.60.0 and below V7.2.63.2 is affected.
- Version V7.2.60.0 and below V7.2.63.2 is affected.
- Version V7.2.60.0 and below V7.2.63.2 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.