{"cve":{"cve_id":"CVE-2026-8037","is_kev":true,"kev_date_added":"2026-08-07","kev_vendor_project":"Progress","kev_product":"LoadMaster","kev_vulnerability_name":"Progress LoadMaster Command Injection Vulnerability","kev_short_description":"Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.","kev_required_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due_date":"2026-08-10","kev_known_ransomware":false,"kev_notes":"https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8037","kev_cwes":["CWE-77"],"epss_score":0.99571,"epss_percentile":0.99944,"epss_as_of":"2026-08-26","description":"OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints","published_at":"2026-06-04T13:13:45.793000Z","last_modified_at":"2026-08-10T20:19:44.760000Z","cvss_v3_score":9.6,"cvss_v3_vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cvss_v3_severity":"CRITICAL","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"active","ssvc_automatable":false,"ssvc_technical_impact":"total","cwes":["CWE-77"],"nvd_references":["https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691"],"vuln_status":"Analyzed","trending_score":null,"is_trending":false,"has_trended":true,"trended_number_one":true,"trending_peak_score":0.6216861518511948,"trending_peak_rank":1,"started_trending_at":"2026-08-12T08:22:22.923833Z","trended_number_one_at":"2026-08-13T20:22:23.029172Z","summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-08-15T12:39:52.997211Z"},"effective_severity":"CRITICAL","badges":["kev","poc","news","was_number_one","epss"],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"A","value_label":"Adjacent"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"C","value_label":"Changed"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"H","value_label":"High"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"progress","vendor_name":"Progress","product_slug":"connection-manager-for-objectscale","product_name":"connection_manager_for_objectscale","version_start":null,"version_start_inclusive":null,"version_end":"7.2.63.2","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*"},{"vendor_slug":"progress","vendor_name":"Progress","product_slug":"ecs-connection-manager","product_name":"ecs_connection_manager","version_start":null,"version_start_inclusive":null,"version_end":"7.2.63.2","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*"},{"vendor_slug":"progress","vendor_name":"Progress","product_slug":"loadmaster","product_name":"LoadMaster","version_start":null,"version_start_inclusive":null,"version_end":"7.2.54.18","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*"},{"vendor_slug":"progress","vendor_name":"Progress","product_slug":"moveit-web-application-firewall","product_name":"moveit_web_application_firewall","version_start":null,"version_start_inclusive":null,"version_end":"7.2.63.2","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:a:progress:moveit_web_application_firewall:*:*:*:*:*:*:*:*"},{"vendor_slug":"progress-software","vendor_name":"Progress Software","product_slug":"ecs-connections-manager","product_name":"ECS Connections Manager","version_start":"V7.2.60.0","version_start_inclusive":true,"version_end":"V7.2.63.2","version_end_inclusive":false,"cpe23_uri":"cve5:progress-software:ecs-connections-manager:V7.2.60.0:V7.2.63.2"},{"vendor_slug":"progress-software","vendor_name":"Progress Software","product_slug":"loadmaster","product_name":"LoadMaster","version_start":"V7.2.60.0","version_start_inclusive":true,"version_end":"V7.2.63.2","version_end_inclusive":false,"cpe23_uri":"cve5:progress-software:loadmaster:V7.2.60.0:V7.2.63.2"},{"vendor_slug":"progress-software","vendor_name":"Progress Software","product_slug":"loadmaster","product_name":"LoadMaster","version_start":"V7.2.45.12","version_start_inclusive":true,"version_end":"V7.2.54.18","version_end_inclusive":false,"cpe23_uri":"cve5:progress-software:loadmaster:V7.2.45.12:V7.2.54.18"},{"vendor_slug":"progress-software","vendor_name":"Progress Software","product_slug":"moveit-waf","product_name":"MOVEit WAF","version_start":"V7.2.60.0","version_start_inclusive":true,"version_end":"V7.2.63.2","version_end_inclusive":false,"cpe23_uri":"cve5:progress-software:moveit-waf:V7.2.60.0:V7.2.63.2"},{"vendor_slug":"progress-software","vendor_name":"Progress Software","product_slug":"object-scale-connection-manager","product_name":"Object Scale Connection Manager","version_start":"V7.2.60.0","version_start_inclusive":true,"version_end":"V7.2.63.2","version_end_inclusive":false,"cpe23_uri":"cve5:progress-software:object-scale-connection-manager:V7.2.60.0:V7.2.63.2"}],"exploit_refs":[{"source":"nuclei","kind":"nuclei","url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-8037.yaml","title":"Progress ADC LoadMaster - Command Injection","author":"watchtowr,DhiyaneshDk","disclosed_at":null}],"news":[{"id":1081,"source":"The Hacker News","url":"https://thehackernews.com/2026/08/progress-kemp-loadmaster-flaw-hits-cisa.html","title":"Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts","summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.\n\nThe vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary","thumbnail_url":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_DF22WirQj4KZe5A4NxYmG3UhC2o4BRQ4AybyFlmr80n5Wkf15sbtMn11P0msoMyAe65WBqMpL2XBsqTiHdDNNH1i6qz11ydD9X4AIOoiaSfCYb1MCe7dfJD0n4TEIc5_83tsMq5zJ5zVpGbpCq7b8rACen1oMvW8XGBbz3T4hy_9J6igpOk0oCDp6vkA/s1600/progress.jpg","author":"info@thehackernews.com (The Hacker News)","published_at":"2026-08-08T06:52:16Z","fetched_at":"2026-08-08T08:14:50.229316Z","trending_score":0.0015521540796399746,"cve_ids":["CVE-2026-8037"]},{"id":299,"source":"The Hacker News","url":"https://thehackernews.com/2026/07/latest-progress-kemp-loadmaster-pre.html","title":"Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts","summary":"A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from eSentire's Threat Response Unit (TRU).\n\nThe Canadian cybersecurity company said it identified exploitation attempts targeting CVE-2026-8037 (CVSS score: 9.6), an operating system (OS) command injection flaw that could be exploited to achieve","thumbnail_url":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEghMOqrFNgwfokWIpvUBFpDUO-So-0focm0a7d9mhocEHiwdB2cHmPQ9q4STjyCr-gVUPK67TYluInMr0_v1omCJVWbd9OVOg6AqVROoxZb44b5BOpxdBb2GECjFw77NhlCf6nWC5oJF3x3KvE3EyDV2pUR3lvROAWjaFs9SOyvzM3qRB6MzEUCFYuVAoCb/s1600/pro-exploit.jpg","author":"info@thehackernews.com (The Hacker News)","published_at":"2026-07-01T13:56:18Z","fetched_at":"2026-07-01T14:50:35.313671Z","trending_score":3.278586921863898e-9,"cve_ids":["CVE-2026-8037"]},{"id":237,"source":"The Hacker News","url":"https://thehackernews.com/2026/06/progress-kemp-loadmaster-flaw-could-let.html","title":"Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth","summary":"A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API.\n\nThe flaw, tracked as&nbsp;CVE-2026-8037, carries a CVSS score of&nbsp;9.8 according to ZDI. A patch is available. If you run LoadMaster with the API enabled, update now.\n\nProgress&nbsp;published its advisory on June","thumbnail_url":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtFZGtJwnGA8dQHmNpd8Pzgx4p0wSq_e2hyphenhyphen2bZwWBQEDK8QPAi2CEOR_Nbns5jhRw9mMSPv6RBe2IqRO1c9fIMvMlUAV14B3VQE7-csMvfMQK6Qr3THGlxQY3C9HiYW_TYHGzok-TWFmMoMkto0OA8fNsQuvADEaJNFQYdIrXXzHGJEhyqpKRC2IFCaRM6/s1600/loadmaster.jpg","author":"info@thehackernews.com (The Hacker News)","published_at":"2026-06-30T07:38:07Z","fetched_at":"2026-06-30T09:31:12.896734Z","trending_score":2.1166173640324487e-9,"cve_ids":["CVE-2026-8037"]}],"references":[{"url":"https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2026-06-04T13:13:45.793000Z","label":"CVE published","source":null},{"type":"cvss_changed","at":"2026-06-28T17:56:17.788615Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:56:17.788615Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:56:17.788615Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"ssvc_changed","at":"2026-06-29T23:46:59.033383Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T23:46:59.033383Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T23:46:59.033383Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"first_article","at":"2026-06-30T07:38:07Z","label":"First news coverage","source":"The Hacker News"},{"type":"ssvc_changed","at":"2026-06-30T13:46:12.619479Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"poc_available","at":"2026-07-02T07:21:34.990832Z","label":"Public PoC available","source":"nuclei"},{"type":"cisa_reported","at":"2026-08-07T00:00:00Z","label":"Added to CISA KEV catalog","source":"kev"},{"type":"ssvc_changed","at":"2026-08-07T18:17:49.987009Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"started_trending","at":"2026-08-12T08:22:22.923833Z","label":"Started trending","source":null},{"type":"reached_number_one","at":"2026-08-13T20:22:23.029172Z","label":"Reached #1 trending","source":null}]}