[KEV] CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability
Active exploitation (KEV)
What to do
- On CISA KEV — actively exploited. Patch immediately.
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
CVE · detail
- CVE-2026-8037KEVEPSS 100%NVD ↗