securityaffairs.com 8/8/2026, 11:40:25 AM · external

CISA flags exploited LoadMaster bug CVE-2026-8037, urges patch

CISA flags exploited LoadMaster bug CVE-2026-8037, urges patch
Developing story vulnerability 8 articles tracked
Progress LoadMaster command injection flaw (CVE-2026-8037) exploited in the wild
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Progress LoadMaster vulnerability, identified as CVE-2026-8037 with a CVSS score of 9.6, to its Known Exploited Vulnerabilities catalog. This vulnerability allows unauthenticated attackers to execute arbitrary commands through OS Command Injection on multiple API endpoints of Progress ADC Products. Active exploitation attempts were observed starting June 29, 2026, although no successful post-compromise activity was detected. Organizations are urged to apply relevant security patches, and federal agencies must address this vulnerability by August 10, 2026.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline