CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability

Summary

A command injection vulnerability (CVE-2026-8037) exists in Progress LoadMaster, allowing unauthenticated attackers to execute arbitrary commands on the appliance through unsanitized input. CISA mandates applying mitigations according to vendor instructions by August 10, 2026, with specific guidance for cloud services and patching prioritization.

IFF Assessment

FOE

This vulnerability allows unauthenticated attackers to execute arbitrary commands, posing a significant risk to the affected infrastructure.

Severity

9.6 Critical

CISA KEV: Listed as actively exploited. Federal patch due: August 10, 2026. Known ransomware use: Unknown.

Defender Context

This critical vulnerability in Progress LoadMaster requires immediate attention for defenders. Organizations must prioritize applying vendor-provided mitigations to prevent unauthorized command execution and potential system compromise. The CISA directive emphasizes risk-based prioritization for security updates, making it crucial to assess the internet exposure of LoadMaster appliances.

Read Full Story →