CVE-2026-8037
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
- Affected products
- Loadmaster, Progress Adc
- Progress Connection Manager For Objectscale
- < 7.2.63.2
- Progress Ecs Connection Manager
- < 7.2.63.2
- Progress Loadmaster
- < 7.2.54.18, 7.2.63.2
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 99.3% (100th percentile)
- Weakness
- CWE-77
- NVD status
- Analyzed
- Published
- 2026-06-04
Workaround
plain text
CVE-2026-8037 at NVD
2 known exploits for CVE-2026-8037
Proof-of-concept code and exploit modules indexed by Sploitus