OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
The attacker sends crafted requests to multiple API endpoints of the LoadMaster device, which do not perform proper input data sanitization (CWE-77 – Improper Neutralization of Special Elements used in a Command). Unvalidated data is passed directly to system calls, which allows injection and execution of arbitrary operating system commands. The attack can be performed from the network segment where the device is accessible, without any credentials.
An unauthenticated attacker gains the ability to remotely execute arbitrary code (RCE) on the LoadMaster device, which in practice means complete takeover of the device, data theft capability, configuration modification, and use of the device as an entry point for further lateral movement in the network.
Apply patches available from the vendor according to references — Progress security bulletin available at: https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691. Until the patch is deployed, it is recommended to restrict access to the device API only to trusted network addresses and monitor traffic directed to LoadMaster API endpoints.
Progress ADC devices — LoadMaster; detailed information on affected versions is provided in the vendor's references (Progress security bulletin from June 2026)
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HProgress Connection Manager For Objectscale
APPProgress< 7.2.63.2Progress Ecs Connection Manager
APPProgress< 7.2.63.2Progress Loadmaster
OSProgress< 7.2.54.187.2.55.0 – 7.2.63.2 (excl.)Progress Moveit Web Application Firewall
APPProgress< 7.2.63.2
CISA KEV — detailsi
- Vendori
- Progress ↗
- Producti
- LoadMaster
- Added to KEVi
- August 7, 2026
- Remediation deadline (US Federal)i
- August 10, 2026(overdue)
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
Related vulnerabilities
Progress LoadMaster – nieuwierzytelnione RCE przez command injection w interfejsie zarządzania
Command Injection w Progress LoadMaster i MOVEit WAF — funkcja przywracania kopii zapasowej
Command Injection w Progress LoadMaster i powiązanych produktach via Geo Location
OS Command Injection w produktach Progress Software — zarządzanie przez interfejs admina
Privilege escalation do root w produktach Progress Software (LoadMaster, ECS, MOVEit WAF)