Security
Loading…

CVE-2026-8037

CRITICALCVSS 9.6Known Exploited
Description

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

Timeline
Published:June 4th, 2026 2:16 PM
Last modified:August 10th, 2026 8:19 PM
Added to KEV:August 7th, 2026
CVSS Scoring

CVSS v3: 9.6 (CRITICAL)

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

progress

Products

connection_manager_for_objectscaleecs_connection_managermoveit_web_application_firewallloadmaster
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute