THREAT OPS › CVEs › CVE-2026-8037
CVE-2026-8037 — Progress LoadMaster Command Injection Vulnerability
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
Vulnerability details
- Affected productsLoadMaster
- KEV remediation due2026-08-10
Related reporting
- ZDI-26-646: Progress Software Kemp LoadMaster escape_quotes Uninitialized Memory Remote Code Execution Vulnerabilityzdi_published
- August 2026 CVE Landscaperecordedfuture
- Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attemptsthehackernews
- [NVD] CVE-2026-8037 (CRITICAL 9.6) — OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpointsnvd
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories
- [CISA KEV] CVE-2026-8037 — Progress LoadMaster: Progress LoadMaster Command Injection Vulnerabilitycisa_kev
- Progress security advisory (AV26-552) – Update 2cccs_ca
- Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)watchtowr
- 6th July – Threat Intelligence Reportcheckpoint_research