Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-08 ยท updated: 2026-08-08 ยท tags: [cve, kev, rce, command-injection, zero-day, load-balancer] ยท confidence: high ยท severity: not-rated ยท affected_sectors: [technology, government] ยท au_impact: true

CVE-2026-8037 โ€” Progress LoadMaster RCE

CVE-2026-8037 is an unauthenticated command-injection remote code execution (RCE) vulnerability in Progress LoadMaster. CISA added it to its Known Exploited Vulnerabilities (KEV) catalogue on 2026-08-07 (due 2026-08-10).

Vulnerability Details

Attribute Detail
CVE CVE-2026-8037
Type Unauthenticated command-injection RCE
Product Progress LoadMaster
Access Unauthenticated
KEV status Added to KEV 2026-08-07 (due 2026-08-10)

Nature of the Flaw

The flaw allows an unauthenticated attacker to execute arbitrary commands on the LoadMaster appliance via unsanitised input in multiple command endpoints.

Impact

Progress LoadMaster is widely deployed as an application-delivery/load-balancing appliance in enterprise and government networks, making prompt patching under BOD 26-04 essential. It is relevant to Australian enterprises and government gateways under the Essential Eight patching schedule.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-08