Knox CVE Database
/
CVE-2026-8037
Critical
9.8

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

Added to the CISA KEV catalog:
August 7, 2026

Overview

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Vulnerability details

Affected vendor
Progress
Affected product
LoadMaster
Weakness type (CWE)
CWE-77

CVE-2026-8037 is a CWE-77 command injection flaw in the Progress Kemp LoadMaster API. Multiple command endpoints in the API accept user-supplied input and pass it to OS command execution routines without sanitization. Because the flaw exists at the API layer, no authentication is required to reach the vulnerable code paths. The same weakness affects ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF products sharing the same codebase in the affected version range.


An attacker sends crafted HTTP API requests containing command injection payloads to the LoadMaster API endpoints. Because no authentication or user interaction is required, the attack is executable by any party with network access to the API. A secondary CNA assessment scores this with adjacent-network reach, indicating some deployments expose the API only on management networks rather than the internet. Successful exploitation yields arbitrary OS command execution on the appliance, producing full confidentiality, integrity, and availability impact.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review LoadMaster API access logs for requests to command endpoints originating from sources outside the defined management network or administrative IP allowlist, particularly sessions with no corresponding authenticated management session.
  • Audit appliance process execution logs for unexpected child processes spawned by the LoadMaster API service, such as shells or network utilities that fall outside the appliance's normal operational baseline.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 10, 2026

Additional hardening

  • Restrict network access to the LoadMaster API to a dedicated management VLAN or allowlisted administrative IP ranges, preventing unauthenticated internet-facing exposure.
  • Disable or firewall the LoadMaster management API port on any appliance where remote API access is not operationally required.
  • Apply firmware upgrades to the fixed versions identified in the vendor bulletin for all affected products, including ECS Connection Manager and Object Scale Connection Manager.
  • Conduct forensic triage per CISA BOD 26-04 requirements before restoring any appliance suspected of exposure to untrusted networks.

Key dates

Published (NVD)
June 4, 2026
Added to CISA KEV
August 7, 2026
Remediation deadline
August 10, 2026
Last updated
August 10, 2026

References

Frequently asked questions

Does CVE-2026-8037 affect my FedRAMP authorization?

If Progress LoadMaster runs inside your authorization boundary, CVE-2026-8037 is your problem to solve. CISA has listed it on the Known Exploited Vulnerabilities catalog with a remediation deadline of August 10, 2026. For a FedRAMP-authorized service, an unpatched KEV in the boundary is an assessor finding: one you either remediate before that date or formally document a mitigation for before your sponsoring agency raises it first.

How does Knox help me handle CVE-2026-8037?

Remediating Progress LoadMaster is your responsibility under the FedRAMP shared-responsibility model; Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage that document the fix for your next assessment. The work of applying the patch is yours. Managing your compliance posture while you do it is not something you have to handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-8037 surfaces, exposure is identified during continuous monitoring rather than surfacing for the first time when an assessor reviews your boundary. That gap matters.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path to authorization. FedRAMP in 90 days for 90% less, without the delays or infrastructure build that traditional authorization demands.

What happens if CVE-2026-8037 isn't remediated by August 10, 2026?

Miss the August 10, 2026 deadline and CVE-2026-8037 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting