CVE-2026-8037: Progress LoadMaster
EPSS77.3%No. 651 of 1739 in KEV
CVE year2026listed the same year
Same vendor in KEV9
Same product1
| Field | Value |
|---|---|
| Vendor | Progress |
| Product | LoadMaster |
| Name | Progress LoadMaster Command Injection Vulnerability |
| Added to KEV | 2026-08-07 |
| US federal due date | 2026-08-10 |
| Ransomware use | Unknown |
| CWE | CWE-77 |
CISA description
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Progress LoadMaster vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-07.