Knox CVE Database
/
CVE-2026-8037
Critical
9.8

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

Added to the CISA KEV catalog:
August 7, 2026

Overview

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Vulnerability details

Affected vendor
Progress
Affected product
LoadMaster
Weakness type (CWE)
CWE-77

Progress LoadMaster contains a command injection flaw (CWE-77) in its management API, where user-supplied input is passed to OS command execution routines without sanitization across multiple API endpoints. When an application fails to neutralize shell metacharacters or command sequences before passing attacker-controlled data to a system shell, the attacker's input is interpreted as commands rather than data. Because the flaw exists in multiple command endpoints, the attack surface is not limited to a single parameter or path, increasing the difficulty of ad-hoc filtering as a compensating control.

An attacker with network access to the LoadMaster management API sends crafted HTTP requests containing injected OS command sequences to one or more of the vulnerable API endpoints. No authentication is required at any stage. Successful injection causes the appliance to execute arbitrary OS commands, yielding full compromise across confidentiality, integrity, and availability of the device. Because LoadMaster functions as a network load balancer and application delivery controller, a fully compromised appliance can affect traffic inspection, certificate handling, and availability of downstream services.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review LoadMaster API access logs for requests to command-handling endpoints originating from IP addresses outside the defined management network, particularly those containing shell metacharacters (semicolons, pipes, backticks, dollar signs) in parameter values or query strings.
  • Audit appliance process trees for unexpected child processes spawned by the API service process, such as shells (sh, bash) or network utilities (curl, wget, nc) that have no corresponding scheduled task or administrative session.
  • Monitor for unexpected outbound connections from the LoadMaster appliance to external hosts, especially those initiated shortly after an inbound API request with no matching authenticated management session.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 10, 2026

Additional hardening

  • Restrict network access to the LoadMaster management API to a dedicated, firewalled management VLAN or jump host; the API must not be reachable from untrusted networks or the internet.
  • Implement an ingress access control list (ACL) on the management interface that permits only explicitly enumerated administrator source addresses, blocking all other sources at the network perimeter.
  • Disable or remove management API exposure on any LoadMaster instance that does not require programmatic administration, reducing the reachable attack surface until patching is complete.
  • Conduct forensic triage per CISA guidance on any appliance that had its management API internet-exposed during the vulnerability window, treating it as potentially compromised regardless of observed indicators.

Key dates

Published (NVD)
June 4, 2026
Added to CISA KEV
August 7, 2026
Remediation deadline
August 10, 2026
Last updated
August 10, 2026

References

Frequently asked questions

Does CVE-2026-8037 affect my FedRAMP authorization?

If Progress LoadMaster runs inside your authorization boundary, yes. CVE-2026-8037 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, which carries a remediation deadline of August 10, 2026. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding — one you either remediate or formally document a mitigation for before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-8037?

Knox doesn't patch your software for you — remediating Progress LoadMaster is your responsibility under the FedRAMP shared responsibility model. What Knox gives you is the pre-authorized, single-tenant boundary to remediate in, plus continuous compliance monitoring and audit-artifact coverage that help you document the fix for your next assessment. The fix is yours to apply; staying compliant while you apply it isn't something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's continuous monitoring, powered by KnoxAI, watches your environment in real time for newly disclosed vulnerabilities and compliance issues. Exposure surfaces as part of ongoing monitoring — not only when an assessor flags it at review time.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path — FedRAMP in 90 days for 90% less, without dependency or delay.

What happens if CVE-2026-8037 isn't remediated by August 10, 2026?

It becomes a POA&M item, and a growing POA&M list is what turns a routine continuous-monitoring review into a real conversation with your agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

What this vulnerability means for your FedRAMP compliance

Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, FedRAMP continuous monitoring puts a hard remediation clock on it. The clock starts on awareness — and missing the deadline can put an Authority to Operate at risk.

FedRAMP remediation deadlines for actively exploited vulnerabilities

FedRAMP ConMon SLAs give cloud providers 30, 90, or 180 days by severity — but KEV-listed flaws carry the tighter CISA deadline shown above. For authorized services, that date is the compliance line that assessors and agency sponsors will check.

How Knox reduces the burden of CVE vulnerabilities

Remediating the flaw is your responsibility under the FedRAMP shared responsibility model — but staying compliant while you fix it isn't something you manage alone. KnoxAI's continuous monitoring surfaces exposure in real time, and Knox keeps your continuous-monitoring evidence and audit artifacts current while you apply the fix. Learn more about the Knox platform.

How to limit your exposure through inherited controls and isolation

Knox's single-tenant architecture gives every customer a dedicated boundary, and 60–80% of FedRAMP controls are inherited from the platform — shrinking the surface you have to patch and prove. See why teams choose Knox.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting