๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability
Summary
Progress LoadMaster has a command injection vulnerability (a type of attack where unsanitized input allows attackers to run unwanted commands) that lets unauthenticated attackers execute arbitrary commands on the LoadMaster appliance. The vulnerability is being actively exploited in the wild, and organizations must apply vendor mitigations by August 10, 2026, following CISA guidance on prioritizing security updates.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions from the Progress LoadMaster Critical Security Bulletin (June 2026). Follow CISA's BOD 26-04 guidance for patching timelines based on asset risk and internet exposure. For cloud services, apply BOD 26-04 guidelines or discontinue use of the product if mitigations are unavailable. See vendor bulletin at: https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691
Vulnerability Details
EPSS: 84.8%
Yes
๐ฅ Actively Exploited
August 6, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-8037
First tracked: August 7, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%