OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
References
| Link | Resource |
|---|---|
| https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691 | Vendor Advisory Patch |
| https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/ | Exploit Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
22 Jul 2026, 20:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
13 Jul 2026, 19:02
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691 - Vendor Advisory, Patch | |
| References | () https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/ - Exploit, Patch, Third Party Advisory | |
| First Time |
Progress
Progress connection Manager For Objectscale Progress ecs Connection Manager Progress loadmaster |
|
| CPE | cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:* cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:* cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:* |
30 Jun 2026, 13:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
04 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-04 14:16
Updated : 2026-07-22 20:10
NVD link : CVE-2026-8037
Mitre link : CVE-2026-8037
CVE.ORG link : CVE-2026-8037
JSON object : View
Products Affected
progress
- ecs_connection_manager
- loadmaster
- connection_manager_for_objectscale
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
