CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
Brief
CISA has added a critical Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog after attackers were observed targeting exposed devices. Tracked as CVE-2026-8037 , the flaw affects Progress LoadMaster and Progress ADC products.
It is a command injection issue that could let an unauthenticated attacker run arbitrary commands on a vulnerable LoadMaster appliance. The vulnerability has a CVSS severity score of 9. 6, placing it in the critical category.
LoadMaster is an application delivery controller and load balancer used by organizations to manage, distribute, and secure network traffic. Because these appliances often sit at critical network points, a successful compromise can provide attackers with a valuable path into an organization’s environment.
