Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands...
Description
Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands on the underlying system.
AI Analyst Comment
Remediation
Actively exploited in the wild (CISA KEV). Apply vendor updates or mitigations promptly.
CISA KEV Details
Deadline: August 10, 2026
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
---METADATA---
VENDOR: Progress
PRODUCT: LoadMaster
AFFECTED_VERSIONS: Progress Software LoadMaster: V7.2.60.0 up to (excluding) V7.2.63.2, V7.2.45.12 up to (excluding) V7.2.54.18; ECS Connections Manager: V7.2.60.0 up to (excluding) V7.2.63.2; Object Scale Connection Manager: V7.2.60.0 up to (excluding) V7.2.63.2; MOVEit WAF: V7.2.60.0 up to (excluding) V7.2.63.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands on the underlying system.
Executive Summary:
A critical command injection vulnerability in Progress LoadMaster is currently being exploited in the wild, posing a severe risk of total system compromise.
Vulnerability Details
CVE-ID: CVE-2026-8037
Affected Software: Progress LoadMaster, ECS Connections Manager, Object Scale Connection Manager, and MOVEit WAF
Affected Versions: See metadata for specific version ranges.
Vulnerability: This vulnerability is a command injection flaw (CWE-77) occurring in the management interfaces of the affected software. It allows an unauthenticated attacker to inject and execute arbitrary operating system commands with high privileges.
Business Impact
Successful exploitation results in full control over the affected appliance, leading to unauthorized access to sensitive data, potential lateral movement within the network, and complete service disruption. Given the CVSS score of 9.5 and confirmed active exploitation, organizations face an extreme risk of data exfiltration and operational downtime.
Remediation Plan
Immediate Action: Apply the vendor-provided security updates immediately to address the vulnerability. If immediate patching is not possible, follow the specific mitigation instructions provided in the official Progress security bulletin.
Proactive Monitoring: Review system logs for unusual process execution or unauthorized command-line activity originating from the load balancer. Monitor network traffic for suspicious patterns directed at management interfaces.
Compensating Controls: Restrict access to the management interface of the LoadMaster appliance to known, trusted administrative IP addresses using firewall rules or ACLs to reduce the attack surface.
Exploitation Status
Public Exploit Available: Yes, a Nuclei detection template exists.
Analyst Notes: This vulnerability is confirmed to be actively exploited in the wild as of August 7, 2026. While weaponized exploit code is not currently confirmed in public repositories, the active exploitation and availability of detection templates necessitate immediate remediation.
Analyst Recommendation
The combination of a 9.5 severity score and active exploitation in the wild makes this a top-priority security event. Administrators must prioritize the application of vendor patches or documented mitigations to prevent unauthorized system access and potential data loss.