All CVEs
Vulnerability intelligence

CVE-2026-4048

CWE-77

OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.

CVSS Score
8.4
High
EPSS — Exploit Probability
2.1%
Riskier than 80% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Apr 21, 2026 · latest Apr 21, 2026

Coverage timeline