type: cve ยท created: 2026-08-08 ยท updated: 2026-08-08 ยท tags: [cve, kev, rce, command-injection, zero-day, load-balancer] ยท confidence: high ยท severity: not-rated ยท affected_sectors: [technology, government] ยท au_impact: true
CVE-2026-8037 โ Progress LoadMaster RCE
CVE-2026-8037 is an unauthenticated command-injection remote code execution (RCE) vulnerability in Progress LoadMaster. CISA added it to its Known Exploited Vulnerabilities (KEV) catalogue on 2026-08-07 (due 2026-08-10).
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-8037 |
| Type | Unauthenticated command-injection RCE |
| Product | Progress LoadMaster |
| Access | Unauthenticated |
| KEV status | Added to KEV 2026-08-07 (due 2026-08-10) |
Nature of the Flaw
The flaw allows an unauthenticated attacker to execute arbitrary commands on the LoadMaster appliance via unsanitised input in multiple command endpoints.
Impact
Progress LoadMaster is widely deployed as an application-delivery/load-balancing appliance in enterprise and government networks, making prompt patching under BOD 26-04 essential. It is relevant to Australian enterprises and government gateways under the Essential Eight patching schedule.
Related Pages
- Cisa Adds Progress Loadmaster Rce Cve 2026 8037 To Known Exploited Vulnerabiliti โ CISA KEV addition incident
Sources: raw/digests/Cyber-Digest-2026-08-08