Known vulnerability record

CVE-2026-8037

Progress LoadMaster Command Injection Vulnerability

Stable IDcve:CVE-2026-8037Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Progress LoadMaster Command Injection Vulnerability

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

Keep the signals separate

CVSS severitycriticalScore 9.6 · source ProgressSoftware
EPSS probability99.3%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-08-07
Ransomware useunknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2026-06-04
CVE modified
2026-08-08
KEV date added
2026-08-07
Dataset fetched
2026-08-21T03:55:00.116Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.