Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
CVE-2026-8037 is a CWE-77 command injection flaw in the Progress Kemp LoadMaster API. Multiple command endpoints in the API accept user-supplied input and pass it to OS command execution routines without sanitization. Because the flaw exists at the API layer, no authentication is required to reach the vulnerable code paths. The same weakness affects ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF products sharing the same codebase in the affected version range.
An attacker sends crafted HTTP API requests containing command injection payloads to the LoadMaster API endpoints. Because no authentication or user interaction is required, the attack is executable by any party with network access to the API. A secondary CNA assessment scores this with adjacent-network reach, indicating some deployments expose the API only on management networks rather than the internet. Successful exploitation yields arbitrary OS command execution on the appliance, producing full confidentiality, integrity, and availability impact.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Progress LoadMaster runs inside your authorization boundary, CVE-2026-8037 is your problem to solve. CISA has listed it on the Known Exploited Vulnerabilities catalog with a remediation deadline of August 10, 2026. For a FedRAMP-authorized service, an unpatched KEV in the boundary is an assessor finding: one you either remediate before that date or formally document a mitigation for before your sponsoring agency raises it first.
Remediating Progress LoadMaster is your responsibility under the FedRAMP shared-responsibility model; Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage that document the fix for your next assessment. The work of applying the patch is yours. Managing your compliance posture while you do it is not something you have to handle alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-8037 surfaces, exposure is identified during continuous monitoring rather than surfacing for the first time when an assessor reviews your boundary. That gap matters.
Book a meeting and Knox maps your path to authorization. FedRAMP in 90 days for 90% less, without the delays or infrastructure build that traditional authorization demands.
Miss the August 10, 2026 deadline and CVE-2026-8037 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









