CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2026-8037

CVSS 9.6v3.1pub. 2026-06-04upd. 2026-08-10

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

🤖 AI Analysis
How it works

The attacker sends crafted requests to multiple API endpoints of the LoadMaster device, which do not perform proper input data sanitization (CWE-77 – Improper Neutralization of Special Elements used in a Command). Unvalidated data is passed directly to system calls, which allows injection and execution of arbitrary operating system commands. The attack can be performed from the network segment where the device is accessible, without any credentials.

Impact

An unauthenticated attacker gains the ability to remotely execute arbitrary code (RCE) on the LoadMaster device, which in practice means complete takeover of the device, data theft capability, configuration modification, and use of the device as an entry point for further lateral movement in the network.

Mitigation & patch

Apply patches available from the vendor according to references — Progress security bulletin available at: https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691. Until the patch is deployed, it is recommended to restrict access to the device API only to trusted network addresses and monitor traffic directed to LoadMaster API endpoints.

Who is affected

Progress ADC devices — LoadMaster; detailed information on affected versions is provided in the vendor's references (Progress security bulletin from June 2026)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Progress Connection Manager For Objectscale

    APP
    Progress
    < 7.2.63.2
  • Progress Ecs Connection Manager

    APP
    Progress
    < 7.2.63.2
  • Progress Loadmaster

    OS
    Progress
    < 7.2.54.187.2.55.0 – 7.2.63.2 (excl.)
  • Progress Moveit Web Application Firewall

    APP
    Progress
    < 7.2.63.2

CISA KEV — detailsi

Vendori
Progress
Producti
LoadMaster
Added to KEVi
August 7, 2026
Remediation deadline (US Federal)i
August 10, 2026(overdue)
Required action (CISA)i

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA descriptioni

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 10 sierpnia 2026
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-1212CRITICAL10.0⚠ KEVPL ✓same product

Progress LoadMaster – nieuwierzytelnione RCE przez command injection w interfejsie zarządzania

CVE-2026-59688HIGH8.4PL ✓same product

Command Injection w Progress LoadMaster i MOVEit WAF — funkcja przywracania kopii zapasowej

CVE-2026-59687HIGH8.4PL ✓same product

Command Injection w Progress LoadMaster i powiązanych produktach via Geo Location

CVE-2026-59686HIGH8.4PL ✓same product

OS Command Injection w produktach Progress Software — zarządzanie przez interfejs admina

CVE-2026-59689HIGH8.0PL ✓same product

Privilege escalation do root w produktach Progress Software (LoadMaster, ECS, MOVEit WAF)