CVE-2026-8037
Description
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
In plain language
AI Worth attentionCVE-2026-8037 is a serious flaw in Progress LoadMaster and related components that lets someone run commands on the server without logging in; you should patch if you run these products, especially if the affected parts are exposed to untrusted networks.
Unauthenticated OS command injection enabling remote code execution exists in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF via unsanitized input in multiple command endpoints, allowing an attacker to execute arbitrary commands on the appliance.
What to do now
- Check whether your business uses Progress LoadMaster, ECS Connections Manager, Object Scale Connection Manager, or MOVEit WAF, and identify the installed version.
- Compare your versions to the fixed releases: update LoadMaster and related managers to V7.2.63.2 (or V7.2.54.18 for LoadMaster), and update MOVEit WAF to V7.2.63.2.
- If you cannot upgrade right away, restrict network access so the affected endpoints are not reachable from untrusted networks (only allow trusted/internal access).
- After upgrading, test that the services still work normally and review logs for any suspicious command/probing activity around the time of exposure.
CVSS Vector Breakdown
AV:AAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attemptsen·The Hacker News·
- ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and Moreen·The Hacker News· Roundup malware
- 6th July – Threat Intelligence Reporten-us·Check Point Research· Advisory ERP Systems data-breach
- Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attemptsen·The Hacker News· Exploited Progress Kemp LoadMaster rce
- Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Authen·The Hacker News· PoC Kemp LoadMaster rce
- Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)en·watchTowr Labs· Research Kemp LoadMaster rce
- Critical Kemp LoadMaster Flaws Expose Network Appliances to RCEen-us·Daily CyberSecurity (securityonline.info)· Patch Progress Kemp LoadMaster rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-8037 and every CVE in our database. Create a free account — no credit card required.
Create Free Account